Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.3 CVE-2025-43448 This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS S… Ipados 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43394 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An a… macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43379 This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14… Ipados 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04 MEDIUM 5.5 CVE-2025-43288 This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypas… macOS 15.7+ Fix from $1,6002025-11-04 HIGH 7.8 CVE-2025-9870 Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escala… Synapse 3.10.730.71519+ Fix from $1,9502025-10-29 HIGH 7.8 CVE-2025-9871 Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privile… Synapse 3.10.730.71519+ Fix from $1,9502025-10-29 HIGH 7.8 CVE-2025-9869 Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privilege… Synapse 3.10.730.71519+ Fix from $1,9502025-10-29 HIGH 7.8 CVE-2025-12341 A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NET.WinForms.exe of the compone… Mitigation only Fix from $1,9502025-10-28 HIGH 8.6 CVE-2025-26625 Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with … Patch available Fix from $1,9502025-10-17 HIGH 7.8 CVE-2025-59281 Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally. Xbox Gaming Services 31.105.17001.0+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-59241 Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to e… Windows 11 24h2 10.0.26100.6899 / 10.0.26200.6899+ Fix from $1,9502025-10-14 HIGH 7.3 CVE-2025-55247 Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. .net 8.0.21 / 9.0.10+ Fix from $1,9502025-10-14 HIGH 7.8 CVE-2025-62363 yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure … Patch available Fix from $1,9502025-10-13 MEDIUM 6.2 CVE-2025-62364 text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerabili… Patch available Fix from $1,6002025-10-13 HIGH 8.5 CVE-2025-9968 A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially cra… Mitigation only Fix from $1,9502025-10-13 MEDIUM 5.4 CVE-2025-11190 The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker contr… Kiwire Mitigation only Fix from $1,6002025-10-10 HIGH 7.0 CVE-2025-11489 A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of… Desktopcommandermcp after 0.2.13 Fix from $1,9502025-10-08 HIGH 7.8 CVE-2025-11462 Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated p… Mitigation only Fix from $1,9502025-10-07 HIGH 8.4 CVE-2025-34191 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deploym… Virtual Appliance Application 20.0.1923 / 22.0.843+ Fix from $1,9502025-09-19 HIGH 7.8 CVE-2025-34194 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (Windows client de… Virtual Appliance Application No fix yet Fix from $1,9502025-09-19 HIGH 7.8 CVE-2025-55245 Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally. Xbox Gaming Services 30.104.13001.0+ Fix from $1,9502025-09-09 HIGH 7.8 CVE-2025-55317 Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges loca… Autoupdate 4.80+ Fix from $1,9502025-09-09 MEDIUM 6.5 CVE-2025-58373 Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore p… Roo Code 3.26.0+ Fix from $1,6002025-09-05 HIGH 7.8 CVE-2025-43726 Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link Resolution Before File Access ('Link Following')" vul… Alienware Command Center 5.10.2.0+ Fix from $1,9502025-09-02 MEDIUM 5.5 CVE-2024-54554 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user d… macOS 15.1+ Fix from $1,6002025-08-29 MEDIUM 6.5 CVE-2025-57749 n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the… N8n 1.106.0+ Fix from $1,6002025-08-20 HIGH 7.3 CVE-2025-8612 AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges… Backupper Workstation Mitigation only Fix from $1,9502025-08-20 HIGH 7.3 CVE-2025-5296 CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protect… Mitigation only Fix from $1,9502025-08-18 HIGH 7.5 CVE-2025-8959 HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designate… Go Getter 1.7.9+ Fix from $1,9502025-08-15 HIGH 8.4 CVE-2025-43490 A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow … Mitigation only Fix from $1,9502025-08-15