Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Git HIGH 7.5
CVE-2021-21300EPSS 89%

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as…

Fix: 2.17.6 / 2.18.5+
Fix from $1,950 2021-03-09
Windows 10 MEDIUM 5.5
CVE-2021-24084

Windows Mobile Device Management Information Disclosure Vulnerability

Patch available
Fix from $1,600 2021-02-25
Connectport X2e Firmware HIGH 7.8
CVE-2020-12878

Digi ConnectPort X2e before 3.2.30.6 allows an attacker to escalate privileges from the python user to root via a symlink attack that uses chown, rel…

Fix: 3.2.30.6+
Fix from $1,950 2021-02-18
Debian Linux HIGH 7.8
CVE-2021-26720

avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att…

Fix: after 0.8-4
Fix from $1,950 2021-02-17
Debian Linux HIGH 8.8
CVE-2021-27229

Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on the Open Webpage text.

Fix: 1.3.4+
Fix from $1,950 2021-02-16
Total Protection MEDIUM 6.1
CVE-2021-23873

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and perform arbi…

Fix: 16.0.30+
Fix from $1,600 2021-02-10
Chrome MEDIUM 6.5
CVE-2021-21131EPSS 8%

Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem restrictions…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,600 2021-02-09
Chrome HIGH 7.8
CVE-2021-21117

Insufficient policy enforcement in Cryptohome in Google Chrome prior to 88.0.4324.96 allowed a local attacker to perform OS-level privilege escalatio…

Fix: 88.0.4324.96+
Fix from $1,950 2021-02-09
Chrome HIGH 8.1
CVE-2021-21125EPSS 8%

Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324.96 allowed a remote attacker to bypass filesystem r…

Fix: 88.0.705.50 / 88.0.4324.96+
Fix from $1,950 2021-02-09
Fedora MEDIUM 5.5
CVE-2020-36241

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extra…

Fix: after 0.2.4
Fix from $1,600 2021-02-05
Oncommand Unified Manager MEDIUM 5.5
CVE-2020-8585

OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY …

Fix: 5.2.5+
Fix from $1,600 2021-01-28
Oras HIGH 7.7
CVE-2021-21272

ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go …

Fix: 0.9.0+
Fix from $1,950 2021-01-25
Ios Xe Sd Wan HIGH 7.5
CVE-2021-1278

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against …

Mitigation only
Fix from $1,950 2021-01-20
Archive Tar HIGH 7.5
CVE-2020-36193 KEVEPSS 71%

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue …

Fix: 7.78 / 8.9.13+
Fix from $1,950 2021-01-18
Staros MEDIUM 6.5
CVE-2021-1145

A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbi…

Fix: 21.19.7+
Fix from $1,600 2021-01-13
Jenkins MEDIUM 6.5
CVE-2021-21602

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier allows reading arbitrary files using the file browser for workspaces and archived artifacts by fol…

Fix: after 2.274
Fix from $1,600 2021-01-13
Fedora HIGH 7.8
CVE-2021-23240

selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacin…

Fix: 1.8.32 / 1.9.5+
Fix from $1,950 2021-01-12
Client MEDIUM 6.5
CVE-2020-27643

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify fil…

Mitigation only
Fix from $1,600 2020-12-29
G Data CRITICAL 9.8
CVE-2020-27172

An issue was discovered in G-Data before 25.5.9.25 using Symbolic links, it is possible to abuse the infected-file restore mechanism to achieve arbit…

Fix: 25.5.9.25+
Fix from $2,300 2020-12-28
Opendkim HIGH 7.8
CVE-2020-35766

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (r…

Fix: after 2.10.3
Fix from $1,950 2020-12-28
Endpoint Protection HIGH 7.1
CVE-2020-28641

In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.

Fix: 1.2.0.849+
Fix from $1,950 2020-12-22
Dbdeployer MEDIUM 6.1
CVE-2020-26277

DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously…

Fix: 1.58.2+
Fix from $1,600 2020-12-21
Ipados HIGH 7.8
CVE-2020-10003

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macO…

Fix: 7.1 / 11.0.1+
Fix from $1,950 2020-12-08
Debian Linux MEDIUM 5.5
CVE-2020-28935

NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that wou…

Fix: 1.13.0 / 4.3.4+
Fix from $1,600 2020-12-07
Go Slug HIGH 7.5
CVE-2020-29529

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with …

Fix: 0.5.0+
Fix from $1,950 2020-12-03
Archer C9 Firmware MEDIUM 6.1
CVE-2020-5797

UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network …

No fix yet
Fix from $1,600 2020-11-21
Pritunl Client Electron HIGH 7.8
CVE-2020-25989

Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may al…

Fix: after 1.2.2550.20
Fix from $1,950 2020-11-19
Antivirus\+ Security 2020 HIGH 7.8
CVE-2020-27697

Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-pr…

Fix: after 16.0
Fix from $1,950 2020-11-18
International Sign\&go HIGH 7.8
CVE-2020-23968

Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSS…

No fix yet
Fix from $1,950 2020-11-10
Archer A7 Firmware MEDIUM 6.2
CVE-2020-5795

UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)_V5_200721 allows an authenticated admin user, with physical access and network access…

No fix yet
Fix from $1,600 2020-11-06