Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.4
CVE-2026-47699
Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafte…
Fix unknown
HIGH 7.1
CVE-2026-17106
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o…
Fix unknown
HIGH 8.1
CVE-2026-19693
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an ar…
Fix unknown
MEDIUM 6.1
CVE-2026-74796
OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious sym…
No fix yet
HIGH 7.5
CVE-2026-19909
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…
No fix yet
HIGH 8.1
CVE-2026-70460
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with…
No fix yet
HIGH 7.1
CVE-2026-63426
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user …
No fix yet
HIGH 7.8
CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a pred…
No fix yet
MEDIUM 6.3
CVE-2026-53799
rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended att…
No fix yet
MEDIUM 5.9
CVE-2026-53801
rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender…
No fix yet
MEDIUM 6.3
CVE-2026-53796
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory h…
No fix yet
HIGH 8.1
CVE-2026-53795
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by speci…
No fix yet
HIGH 7.4
CVE-2026-53793
rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement b…
No fix yet
HIGH 7.1
CVE-2026-53784
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroo…
No fix yet
HIGH 7.1
CVE-2026-53785
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory t…
No fix yet
HIGH 8.1
CVE-2026-53783
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows a…
No fix yet
HIGH 7.0
CVE-2026-15994
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that …
No fix yet
HIGH 7.1
CVE-2026-12036
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a loc…
No fix yet
HIGH 8.2
CVE-2026-73613
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authen…
No fix yet
CRITICAL 9.9
CVE-2026-63293
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un…
No fix yet
CRITICAL 9.9
CVE-2026-63294
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf…
No fix yet
MEDIUM 6.7
CVE-2026-65680
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Onedrive
No fix yet
MEDIUM 5.5
CVE-2026-72971
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att…
Windows 11 26h1
10.0.28000.2704+
MEDIUM 5.5
CVE-2026-70348
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Windows 11 24h2
10.0.26100.9106 / 10.0.26200.9106+
HIGH 7.8
CVE-2026-62832
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo…
Windows 10 21h2
10.0.19044.7663 / 10.0.19045.7663+
HIGH 7.8
CVE-2026-62812
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
No fix yet
HIGH 7.8
CVE-2026-62803
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.8
CVE-2026-62807
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
No fix yet
HIGH 7.8
CVE-2026-62776
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
No fix yet
HIGH 7.8
CVE-2026-62761
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Windows 10 1607
No fix yet