Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.4 CVE-2026-47699 Confidential Containers Guest Components provides guest tools and components for confidential container workloads. From 0.16.0 until 0.20.0, a crafte… Fix unknown Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-17106 The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o… Fix unknown Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-19693 extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an ar… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.1 CVE-2026-74796 OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious sym… No fix yet Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-19909 PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu… No fix yet Fix from $4,9002026-08-14 HIGH 8.1 CVE-2026-70460 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-63426 During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow an authenticated local user … No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-53803 rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a pred… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.3 CVE-2026-53799 rsync before 3.5.0 contains a symlink race condition vulnerability that allows local attackers to cause rsync to apply arbitrary ACLs or extended att… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-53801 rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's directory scanning logic that allows attackers to cause the sender… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-53796 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory h… No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-53795 rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the intended destination tree by speci… No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-53793 rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended inner-module root confinement b… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-53784 rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intended module root when use chroo… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-53785 rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the intended destination directory t… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-53783 rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricted shell wrapper that allows a… No fix yet Fix from $4,9002026-08-13 HIGH 7.0 CVE-2026-15994 During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that … No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-12036 An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a loc… No fix yet Fix from $4,9002026-08-13 HIGH 8.2 CVE-2026-73613 filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authen… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.9 CVE-2026-63293 A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-63294 A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf… No fix yet Fix from $5,7502026-08-12 MEDIUM 6.7 CVE-2026-65680 Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. Onedrive No fix yet Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-72971 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att… Windows 11 26h1 10.0.28000.2704+ Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-70348 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-62832 Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo… Windows 10 21h2 10.0.19044.7663 / 10.0.19045.7663+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62812 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62803 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62807 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62776 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62761 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11