Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Internet Security HIGH 7.1
CVE-2026-27748

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged…

Fix: 1.1.114.3113+
Fix from $1,950 2026-03-05
Bentoml HIGH 7.8
CVE-2026-27905

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile(…

Fix: 1.4.36+
Fix from $1,950 2026-03-03
Optimizer HIGH 7.8
CVE-2026-25906

Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged at…

Fix: 6.3.1.0+
Fix from $1,950 2026-03-03
Wise Force Deleter HIGH 7.1
CVE-2025-66680

An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a craf…

Fix: after 1.5.7.59
Fix from $1,950 2026-03-03
Android HIGH 8.4
CVE-2025-48582

In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could l…

Mitigation only
Fix from $1,950 2026-03-02
Zed HIGH 7.1
CVE-2026-27967

Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading…

Fix: 0.225.9+
Fix from $1,950 2026-02-26
Pcmanager HIGH 7.4
CVE-2025-63946

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute progr…

Fix: after 17.10.28554.205
Fix from $1,950 2026-02-23
Ioa HIGH 7.4
CVE-2025-63945

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs …

Fix: 210.9.28693.62001+
Fix from $1,950 2026-02-23
Unclassified MEDIUM 5.5
CVE-2026-2490

RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose …

Patch available
Fix from $1,600 2026-02-20
Unclassified HIGH 7.8
CVE-2026-2627

A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\micr…

No fix yet
Fix from $1,950 2026-02-17
Unclassified HIGH 8.5
CVE-2026-26225

Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege e…

Mitigation only
Fix from $1,950 2026-02-12
macOS HIGH 7.8
CVE-2026-20610

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.

Fix: 26.3+
Fix from $1,950 2026-02-11
Qts CRITICAL 9.8
CVE-2025-66277

A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…

Mitigation only
Fix from $2,300 2026-02-11
Windows App HIGH 7.0
CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

Fix: 11.3.2+
Fix from $1,950 2026-02-10
Forticlient HIGH 7.1
CVE-2025-62676

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7…

Fix: 7.2.13 / 7.4.5+
Fix from $1,950 2026-02-10
Endpoint Configuration Toolset Solution HIGH 7.8
CVE-2025-15310

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Fix: 1.40.37 / 3.17.10195+
Fix from $1,950 2026-02-10
Euss HIGH 7.1
CVE-2025-15313

Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.

Fix: 1.17.41 / 1.18.28+
Fix from $1,950 2026-02-10
End User Cx HIGH 8.1
CVE-2025-15314

Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.

Fix: 1.4.1175 / 1.6.926+
Fix from $1,950 2026-02-10
Patch Endpoint Tools HIGH 7.8
CVE-2025-15319

Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.

Fix: 3.17.10207 / 10.1.50+
Fix from $1,950 2026-02-09
End User Notifications MEDIUM 6.0
CVE-2025-15318

Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.

Fix: 1.18.10079 / 10.0.14+
Fix from $1,600 2026-02-09
Unclassified MEDIUM 6.6
CVE-2026-21419

Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Access ('Link Following') vulnera…

Mitigation only
Fix from $1,600 2026-02-09
Engage MEDIUM 6.6
CVE-2025-15324

Tanium addressed a documentation issue in Engage.

Fix: 1.3.37 / 1.6.193+
Fix from $1,600 2026-02-05
Enforce MEDIUM 5.0
CVE-2025-15328

Tanium addressed an improper link resolution before file access vulnerability in Enforce.

Fix: 2.7.314 / 2.8.544+
Fix from $1,600 2026-02-05
Compressing HIGH 7.8
CVE-2026-24884

Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring…

Fix: 1.10.4+
Fix from $1,950 2026-02-04
Cd3510 Firmware MEDIUM 6.1
CVE-2025-69429

The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or t…

Fix: after 1.9.12
Fix from $1,600 2026-02-03
Dm2 Firmware MEDIUM 6.1
CVE-2025-69430

An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (vers…

Fix: after 1.9.12
Fix from $1,600 2026-02-03
Q2c Firmware MEDIUM 6.1
CVE-2025-69431

The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic…

Fix: after 1.1.0210050
Fix from $1,600 2026-02-03
Vx800v Firmware MEDIUM 6.3
CVE-2025-15541

Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files…

Fix: 800.0.11+
Fix from $1,600 2026-01-29
Digital Employee Experience HIGH 7.1
CVE-2026-23563

Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before ve…

Fix: 26.1+
Fix from $1,950 2026-01-29
Tar HIGH 8.2
CVE-2026-24842

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path res…

Fix: 7.5.7+
Fix from $1,950 2026-01-28