Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Unclassified MEDIUM 5.0
CVE-2026-12391

An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.5
CVE-2026-61371

Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink targ…

Mitigation only
Fix from $1,950 2026-07-15
Rclone HIGH 8.8
CVE-2026-54572

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclon…

Fix: 1.74.4+
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-53486

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…

Mitigation only
Fix from $2,300 2026-07-14
.net MEDIUM 5.5
CVE-2026-50526

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

Fix: 8.0.29 / 9.0.18+
Fix from $1,600 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50469

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges l…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Pc Manager HIGH 8.8
CVE-2026-50438

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.22.1.0+
Fix from $1,950 2026-07-14
Pc Manager HIGH 7.8
CVE-2026-58636

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-07-14
Windows 10 21h2 HIGH 7.3
CVE-2026-50364

Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49791

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to e…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-49180

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Unclassified HIGH 7.7
CVE-2026-15392

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method buil…

Mitigation only
Fix from $1,950 2026-07-14
Internet Security HIGH 7.0
CVE-2026-6851

An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and…

Fix: 27.0.58.315+
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.3
CVE-2026-15629

A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesy…

Mitigation only
Fix from $1,600 2026-07-14
Unclassified MEDIUM 5.3
CVE-2026-15621

A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of…

No fix yet
Fix from $1,600 2026-07-14
Unclassified MEDIUM 6.6
CVE-2026-62239

FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hoppe…

Patch available
Fix from $1,600 2026-07-13
Openclaw HIGH 7.1
CVE-2026-62189

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform act…

Fix: 2026.6.9+
Fix from $1,950 2026-07-13
Anydesk MEDIUM 5.5
CVE-2026-15681

AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service cond…

Mitigation only
Fix from $1,600 2026-07-13
Anydesk MEDIUM 5.5
CVE-2026-15682

AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service c…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15684

Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o…

Mitigation only
Fix from $1,950 2026-07-13
Imagemagick MEDIUM 5.3
CVE-2026-61858

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attac…

Fix: 6.9.13-51 / 7.1.2-26+
Fix from $1,600 2026-07-11
Decompress MEDIUM 5.5
CVE-2026-39243

decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When process…

Fix: after 4.2.1
Fix from $1,600 2026-07-09
Decompress HIGH 7.5
CVE-2026-39246

decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.link…

Fix: after 4.2.1
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.5
CVE-2026-58198

ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predicta…

Patch available
Fix from $1,600 2026-07-09
Unclassified HIGH 8.7
CVE-2026-14891

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-55668

File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in s…

Patch available
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.5
CVE-2026-14904

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual deskt…

Mitigation only
Fix from $1,600 2026-07-07
Crawl4ai CRITICAL 9.6
CVE-2026-57571

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w…

Fix: 0.9.0+
Fix from $2,300 2026-07-06
Hugo MEDIUM 5.5
CVE-2026-50135

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat …

Fix: 0.161.1+
Fix from $1,600 2026-07-06