Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Hugo MEDIUM 6.5
CVE-2026-58403

Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outsi…

Fix: 0.163.1+
Fix from $1,600 2026-07-06
Pydantic Settings MEDIUM 5.3
CVE-2026-58203

pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource reads secret values from files i…

Fix: 2.14.2+
Fix from $1,600 2026-07-06
Edge Chromium HIGH 7.4
CVE-2026-57991

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose informa…

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-25718

Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through s…

Patch available
Fix from $2,300 2026-07-03
Device Management Agent HIGH 7.8
CVE-2026-41121

Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. …

Fix: 26.05+
Fix from $1,950 2026-07-01
Claude Code MEDIUM 6.1
CVE-2026-46406

Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/t…

Fix: 2.1.128+
Fix from $1,600 2026-06-29
Claude Code HIGH 8.8
CVE-2026-55607

Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and nav…

Fix: 2.1.163+
Fix from $1,950 2026-06-29
Unclassified HIGH 7.1
CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extend…

Mitigation only
Fix from $1,950 2026-06-29
Unclassified HIGH 7.1
CVE-2026-54371

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate p…

Mitigation only
Fix from $1,950 2026-06-29
Budibase CRITICAL 9.6
CVE-2026-54352

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a b…

Fix: 3.39.9+
Fix from $2,300 2026-06-26
Dokku HIGH 8.8
CVE-2026-45405

Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary di…

Fix: 0.38.2+
Fix from $1,950 2026-06-26
Unclassified HIGH 8.2
CVE-2026-55667

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-54094

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6…

Mitigation only
Fix from $1,950 2026-06-25
Cursor CRITICAL 9.8
CVE-2026-50549

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the…

Fix: 3.0+
Fix from $2,300 2026-06-25
Chrome Devtools Mcp MEDIUM 6.1
CVE-2026-53765

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.20.0 until 1.1.0, The chrom…

Fix: 1.1.0+
Fix from $1,600 2026-06-24
Chrome Devtools Mcp MEDIUM 6.1
CVE-2026-53766

Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContex…

Fix: 1.1.0+
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.0
CVE-2026-52811

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload tar…

Patch available
Fix from $2,300 2026-06-24
Unclassified HIGH 8.0
CVE-2026-23879

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below c…

Mitigation only
Fix from $1,950 2026-06-24
Proftpd HIGH 8.1
CVE-2026-35025

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL …

Fix: after 1.3.9b
Fix from $1,950 2026-06-24
Unclassified HIGH 7.8
CVE-2026-11940

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deepe…

Patch available
Fix from $1,950 2026-06-23
Unclassified MEDIUM 5.5
CVE-2026-56692

NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-…

Patch available
Fix from $1,600 2026-06-23
Wyse Management Suite HIGH 7.8
CVE-2026-44274

Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged …

Fix: 2605+
Fix from $1,950 2026-06-22
Langchain MEDIUM 5.5
CVE-2026-55443

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths…

Fix: 1.3.9+
Fix from $1,600 2026-06-22
Unclassified MEDIUM 6.1
CVE-2026-56236

Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without va…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.1
CVE-2026-47833

setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm …

Mitigation only
Fix from $1,600 2026-06-18
Unclassified MEDIUM 6.5
CVE-2026-47277

Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos from files inside cloned app-sto…

Mitigation only
Fix from $1,600 2026-06-17
Malware Protection Engine HIGH 7.0
CVE-2026-50656EPSS 11%

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP…

No fix yet
Fix from $1,950 2026-06-16
Fedora HIGH 7.8
CVE-2026-54230

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell …

Mitigation only
Fix from $1,950 2026-06-13
Kitty HIGH 7.1
CVE-2026-54056

Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwr…

Fix: 0.47.2+
Fix from $1,950 2026-06-12
Kitty MEDIUM 5.0
CVE-2026-54055

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmis…

Fix: 0.47.2+
Fix from $1,600 2026-06-12