Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Malware Protection Engine HIGH 7.8
CVE-2026-41091 KEVEPSS 10%

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Fix: 1.1.26040.8+
Fix from $1,950 2026-05-20
Rsync MEDIUM 6.3
CVE-2026-43619

Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unli…

Fix: after 3.4.2
Fix from $1,600 2026-05-20
Unclassified MEDIUM 5.3
CVE-2026-34883

An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability a…

Mitigation only
Fix from $1,600 2026-05-19
Unclassified HIGH 7.4
CVE-2026-45539

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumer…

No fix yet
Fix from $1,950 2026-05-15
Gix Fs HIGH 7.8
CVE-2026-44471

gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide,…

Fix: 0.21.1+
Fix from $1,950 2026-05-13
Empirbus Wireless Display Unit Firmware HIGH 7.5
CVE-2025-27850

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is u…

Mitigation only
Fix from $1,950 2026-05-13
Vm2 HIGH 8.5
CVE-2026-43998

vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing s…

No fix yet
Fix from $1,950 2026-05-13
Claude Desktop HIGH 7.8
CVE-2026-44470

The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the Cowo…

Fix: 1.3834.0+
Fix from $1,950 2026-05-13
Unclassified MEDIUM 6.0
CVE-2026-6959

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user thro…

Mitigation only
Fix from $1,600 2026-05-12
Unclassified MEDIUM 6.0
CVE-2026-8052

HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user throug…

Mitigation only
Fix from $1,600 2026-05-12
Visual Studio Code MEDIUM 5.0
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …

Fix: 1.119.1+
Fix from $1,600 2026-05-12
Unclassified HIGH 8.5
CVE-2026-43989

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age…

Patch available
Fix from $1,950 2026-05-12
Unclassified HIGH 8.8
CVE-2021-47949

CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by expl…

No fix yet
Fix from $1,950 2026-05-10
Unclassified HIGH 7.5
CVE-2026-42574

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk coul…

Patch available
Fix from $1,950 2026-05-09
Praisonai HIGH 7.5
CVE-2026-44340

PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack…

Fix: 4.6.37+
Fix from $1,950 2026-05-08
Go MEDIUM 5.3
CVE-2026-39819

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to t…

Fix: 1.25.10 / 1.26.3+
Fix from $1,600 2026-05-07
Unclassified HIGH 7.0
CVE-2026-7832

A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The m…

Mitigation only
Fix from $1,950 2026-05-05
Intellij Idea HIGH 7.5
CVE-2026-41882

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-i…

Mitigation only
Fix from $1,950 2026-04-30
Dell\/alienware Purchased Apps HIGH 7.1
CVE-2026-27105

Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A…

Fix: 1.1.31.0+
Fix from $1,950 2026-04-29
Unclassified HIGH 8.8
CVE-2026-5161

Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About …

Mitigation only
Fix from $1,950 2026-04-29
Openclaw CRITICAL 9.6
CVE-2026-41397

OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du…

Fix: 2026.3.31+
Fix from $2,300 2026-04-28
Openclaw HIGH 8.1
CVE-2026-41364

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files.…

Fix: 2026.3.31+
Fix from $1,950 2026-04-28
Spring Boot MEDIUM 6.7
CVE-2026-40977

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one fi…

Fix: 2.7.33 / 3.3.19+
Fix from $1,600 2026-04-28
Opentelemetry Ebpf Instrumentation HIGH 8.4
CVE-2026-41433

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java …

Fix: 0.8.0+
Fix from $1,950 2026-04-24
Radare2 HIGH 7.8
CVE-2026-6941

radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…

Fix: 6.1.4+
Fix from $1,950 2026-04-23
Unclassified HIGH 7.4
CVE-2026-33694

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condit…

Mitigation only
Fix from $1,950 2026-04-23
Froxlor HIGH 7.5
CVE-2026-41231

Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supp…

Fix: 2.3.6+
Fix from $1,950 2026-04-23
Coreutils MEDIUM 6.6
CVE-2026-35365

The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of…

Fix: 0.7.0+
Fix from $1,600 2026-04-22
Coreutils HIGH 7.7
CVE-2026-35349

A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check …

Fix: 0.7.0+
Fix from $1,950 2026-04-22
Coreutils MEDIUM 5.3
CVE-2026-35345

A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. U…

No fix yet
Fix from $1,600 2026-04-22