Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Compressing HIGH 7.8
CVE-2026-40931

Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical strin…

Fix: 1.10.5 / 2.1.1+
Fix from $1,950 2026-04-21
Python Dotenv MEDIUM 6.6
CVE-2026-28684

python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, `set_key()` and `unset_key()`…

Fix: 1.2.2+
Fix from $1,600 2026-04-20
Weblate HIGH 7.7
CVE-2026-34242

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following …

Fix: 5.17+
Fix from $1,950 2026-04-15
Unclassified MEDIUM 5.5
CVE-2026-20161

A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbit…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified MEDIUM 6.6
CVE-2026-4135

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local…

Mitigation only
Fix from $1,600 2026-04-15
Unclassified HIGH 7.1
CVE-2026-0827

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vanta…

Mitigation only
Fix from $1,950 2026-04-15
Windows 10 1607 MEDIUM 5.5
CVE-2026-32212

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Go MEDIUM 6.4
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the sym…

Fix: 1.25.9 / 1.26.2+
Fix from $1,600 2026-04-08
Flatpak CRITICAL 10.0
CVE-2026-34078

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options…

Fix: after 1.16.3
Fix from $2,300 2026-04-07
macOS HIGH 8.7
CVE-2025-43257

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbo…

Fix: 15.6+
Fix from $1,950 2026-04-02
Tinacms\/cli HIGH 8.3
CVE-2026-34603

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal checks to the dev media rout…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Tinacms\/graphql HIGH 8.8
CVE-2026-34604

Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containment checks in FilesystemBridge.…

Fix: after 2.2.1
Fix from $1,950 2026-04-01
Claude Sdk For Python MEDIUM 5.3
CVE-2026-34452

The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the async local f…

Fix: 0.87.0+
Fix from $1,600 2026-03-31
Buildkit HIGH 7.5
CVE-2026-33748

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insuf…

Fix: 0.28.1+
Fix from $1,950 2026-03-27
Ipados MEDIUM 6.2
CVE-2026-28866

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS S…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Ipados MEDIUM 5.5
CVE-2026-20694

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.…

Fix: 14.8.4 / 15.7.4+
Fix from $1,600 2026-03-25
macOS MEDIUM 5.5
CVE-2026-20633

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An a…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Openclaw HIGH 7.8
CVE-2026-32054

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local a…

Fix: 2026.2.25+
Fix from $1,950 2026-03-21
Openclaw HIGH 7.5
CVE-2026-32024

OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers to read arbitrary files outsi…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 5.5
CVE-2026-32020

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-r…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 8.8
CVE-2026-32013

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files.set methods that allows readi…

Fix: 2026.2.25+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-31990

OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to validate destination symlinks duri…

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Jenkins HIGH 8.8
CVE-2026-33001

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing…

Fix: 2.541.3 / 2.555+
Fix from $1,950 2026-03-18
Openclaw MEDIUM 5.3
CVE-2026-22180

OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allows writes outside intended ro…

Fix: 2026.3.2+
Fix from $1,600 2026-03-18
Unclassified MEDIUM 6.8
CVE-2026-2808

HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authent…

Mitigation only
Fix from $1,600 2026-03-12
Himmelblau HIGH 7.8
CVE-2026-31979

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelblaud-tasks daemon, running as r…

Fix: 2.3.8 / 3.1.0+
Fix from $1,950 2026-03-11
Wegia HIGH 7.5
CVE-2026-31894

WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP'…

Patch available
Fix from $1,950 2026-03-11
Windows 10 1607 HIGH 7.8
CVE-2026-25187

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Imagemagick MEDIUM 6.3
CVE-2026-28689

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, domain="path…

Fix: 6.9.13-41 / 7.1.2-16+
Fix from $1,600 2026-03-10
Tar MEDIUM 6.3
CVE-2026-29786

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction …

Fix: 7.5.10+
Fix from $1,600 2026-03-07