Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Pnpm MEDIUM 6.5
CVE-2026-24056

pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads the…

Fix: 10.28.2+
Fix from $1,600 2026-01-26
Miniserve MEDIUM 6.8
CVE-2025-67124

A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary f…

No fix yet
Fix from $1,600 2026-01-23
Opencryptoki MEDIUM 6.8
CVE-2026-23893

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running i…

Patch available
Fix from $1,600 2026-01-22
Unclassified HIGH 7.1
CVE-2026-24046

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlin…

Patch available
Fix from $1,950 2026-01-21
Unclassified MEDIUM 6.3
CVE-2026-24047

Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend an…

Patch available
Fix from $1,600 2026-01-21
Unclassified MEDIUM 5.5
CVE-2025-13154

An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to…

Mitigation only
Fix from $1,600 2026-01-14
Windows 11 24h2 HIGH 7.8
CVE-2026-20941

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
Filelock MEDIUM 5.3
CVE-2026-22701

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock im…

Fix: 3.20.3+
Fix from $1,600 2026-01-10
Unclassified HIGH 7.3
CVE-2025-12838

MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affec…

Mitigation only
Fix from $1,950 2025-12-23
Total Security HIGH 7.8
CVE-2023-53973

Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system …

No fix yet
Fix from $1,950 2025-12-22
Weblate MEDIUM 6.5
CVE-2025-68279

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf…

Fix: 5.15.1+
Fix from $1,600 2025-12-18
Filelock MEDIUM 6.5
CVE-2025-68146

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows loca…

Fix: 3.20.1+
Fix from $1,600 2025-12-16
Unclassified MEDIUM 6.2
CVE-2025-14693

A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads …

Mitigation only
Fix from $1,600 2025-12-15
macOS MEDIUM 5.5
CVE-2025-43461

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user d…

Fix: 26.1+
Fix from $1,600 2025-12-12
macOS MEDIUM 5.5
CVE-2025-43381

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to delete protected…

Fix: 26.1+
Fix from $1,600 2025-12-12
Antivirus HIGH 7.8
CVE-2025-7073

A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate pri…

Fix: 7.9.20.515 / 27.0.47.241+
Fix from $1,950 2025-12-10
Argo Workflows HIGH 7.5
CVE-2025-66626

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versio…

Fix: 3.6.14 / 3.7.5+
Fix from $1,950 2025-12-09
Encryption MEDIUM 6.6
CVE-2025-46636

Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged…

Fix: 11.12.1+
Fix from $1,600 2025-12-09
Encryption HIGH 7.3
CVE-2025-46637

Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local maliciou…

Fix: 11.12.1+
Fix from $1,950 2025-12-09
Static Web Server HIGH 8.6
CVE-2025-67487

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (s…

Fix: after 2.40.0
Fix from $1,950 2025-12-09
Aquarius HIGH 7.7
CVE-2025-65843

Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application f…

No fix yet
Fix from $1,950 2025-12-03
Unclassified HIGH 8.5
CVE-2025-34352

JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\S…

Mitigation only
Fix from $1,950 2025-12-02
Windows 11 24h2 HIGH 7.8
CVE-2025-60710 KEV

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,950 2025-11-11
Windows 10 1607 MEDIUM 5.5
CVE-2025-59510

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to d…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,600 2025-11-11
Unclassified MEDIUM 6.7
CVE-2025-24918

Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware U…

Mitigation only
Fix from $1,600 2025-11-11
Axis Os MEDIUM 6.8
CVE-2025-5718

The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device…

Fix: 12.6.30+
Fix from $1,600 2025-11-11
Enterprise Server HIGH 7.2
CVE-2025-11578

A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH acces…

Fix: 3.14.20 / 3.15.15+
Fix from $1,950 2025-11-10
Kubevirt MEDIUM 5.0
CVE-2025-64437

KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the laun…

Fix: 1.5.3+
Fix from $1,600 2025-11-07
Unclassified MEDIUM 5.6
CVE-2025-12418

Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a loca…

Mitigation only
Fix from $1,600 2025-11-07
macOS MEDIUM 5.5
CVE-2025-43446

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An…

Fix: 14.8.2 / 15.7.2+
Fix from $1,600 2025-11-04