Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
macOS MEDIUM 5.5
CVE-2025-46293

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user d…

Fix: 15.4+
Fix from $1,600 2026-06-11
Unclassified MEDIUM 6.1
CVE-2026-45384

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary …

Mitigation only
Fix from $1,600 2026-06-10
Assisted Migration Agent CRITICAL 9.6
CVE-2026-53476

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal…

Fix: 2026-06-07+
Fix from $2,300 2026-06-10
Unclassified MEDIUM 6.5
CVE-2026-11853

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts …

Mitigation only
Fix from $1,600 2026-06-10
Unclassified HIGH 7.3
CVE-2026-11837

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() inst…

Mitigation only
Fix from $1,950 2026-06-10
Pc Manager HIGH 7.8
CVE-2026-50511

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.3
CVE-2026-44275

Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A…

Mitigation only
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45586

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevat…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
.net MEDIUM 5.5
CVE-2026-45491

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

Fix: 8.0.28 / 9.0.17+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-42989

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Unclassified MEDIUM 6.0
CVE-2026-28262

Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile…

Mitigation only
Fix from $1,600 2026-06-09
Unclassified MEDIUM 6.5
CVE-2026-11322

Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks …

Patch available
Fix from $1,600 2026-06-04
Unclassified HIGH 8.8
CVE-2026-41236

Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path…

Mitigation only
Fix from $1,950 2026-06-04
Unclassified MEDIUM 5.1
CVE-2026-42795

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. …

Patch available
Fix from $1,600 2026-06-02
Unclassified HIGH 7.1
CVE-2026-49135

CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or ta…

Patch available
Fix from $1,950 2026-06-01
Airflow MEDIUM 6.5
CVE-2026-40861

A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (rea…

Fix: 3.2.2+
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.0
CVE-2026-6892

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit …

Mitigation only
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.0
CVE-2026-6891

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login priv…

Mitigation only
Fix from $1,600 2026-05-29
Portainer CRITICAL 9.9
CVE-2026-44881

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…

Fix: 2.33.8 / 2.39.2+
Fix from $2,300 2026-05-28
Unclassified HIGH 7.7
CVE-2026-9804

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerabili…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified HIGH 7.9
CVE-2026-44711

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files ena…

Mitigation only
Fix from $1,950 2026-05-27
Pipeline\ HIGH 7.5
CVE-2026-48921

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers …

Fix: 798.v5cc688825312+
Fix from $1,950 2026-05-27
Fastnetmon MEDIUM 5.5
CVE-2026-48693

FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defau…

Fix: after 1.2.9
Fix from $1,600 2026-05-26
Unclassified CRITICAL 9.9
CVE-2026-7374

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single na…

Mitigation only
Fix from $2,300 2026-05-26
\ CRITICAL 9.1
CVE-2026-42496

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() …

Fix: 3.08+
Fix from $2,300 2026-05-26
\ HIGH 7.5
CVE-2026-42497

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() pas…

Fix: 3.08+
Fix from $1,950 2026-05-26
Bentoml MEDIUM 5.5
CVE-2026-40610

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build pa…

Fix: 1.4.39+
Fix from $1,600 2026-05-22
Apex One HIGH 7.8
CVE-2025-71212

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations.…

Fix: 14.0.0.14136 / 14.0.20315+
Fix from $1,950 2026-05-21
Unclassified HIGH 8.1
CVE-2026-44051

An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite…

Mitigation only
Fix from $1,950 2026-05-21
Windows Admin Center HIGH 7.8
CVE-2026-42834

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 0.72.0.0+
Fix from $1,950 2026-05-20