Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.3 CVE-2025-54798 tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory … Tmp 0.2.4+ Fix from $1,6002025-08-07 HIGH 7.8 CVE-2025-36611 Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Followi… Encryption 11.11.0.1 / 11.11.0.2+ Fix from $1,9502025-07-30 MEDIUM 6.5 CVE-2025-43252 This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access … macOS 15.6+ Fix from $1,6002025-07-30 CRITICAL 9.8 CVE-2025-43220 This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS V… Ipados 13.7.7 / 14.7.7+ Fix from $2,3002025-07-30 HIGH 8.5 CVE-2025-23267 NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by usi… Mitigation only Fix from $1,9502025-07-17 HIGH 8.6 CVE-2025-7012 An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper sy… Mitigation only Fix from $1,9502025-07-13 HIGH 7.8 CVE-2025-52837 Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could … Password Manager 5.8.0.1330+ Fix from $1,9502025-07-10 HIGH 8.0 CVE-2025-48384 KEV Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full acc… Git 2.43.7 / 2.44.4+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49738 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.17.4.0+ Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-49739 Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. Visual Studio 15.9.75 / 16.11.49+ Fix from $1,9502025-07-08 HIGH 7.3 CVE-2025-49680 Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-48820 Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-48799 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 MEDIUM 6.0 CVE-2025-21195 Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. Azure Service Fabric 10.1+ Fix from $1,6002025-07-08 HIGH 8.8 CVE-2025-41666 A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file … Mitigation only Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-41667 A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to… Mitigation only Fix from $1,9502025-07-08 HIGH 8.8 CVE-2025-41668 A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and e… Mitigation only Fix from $1,9502025-07-08 HIGH 7.3 CVE-2025-53109 Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6… Patch available Fix from $1,9502025-07-02 HIGH 7.1 CVE-2025-3771 A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system f… System Information Reporter after 1.0.3 Fix from $1,9502025-06-26 CRITICAL 9.3 CVE-2025-52936 Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2. Patch available Fix from $2,3002025-06-23 HIGH 7.8 CVE-2025-30640 A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations… Deep Security Agent 20.0.1+ Fix from $1,9502025-06-17 HIGH 7.8 CVE-2025-30641 A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate… Deep Security Agent 20.0.1+ Fix from $1,9502025-06-17 MEDIUM 5.5 CVE-2025-30642 A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on… Deep Security Agent 20.0.1+ Fix from $1,6002025-06-17 HIGH 7.8 CVE-2025-49156 A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installation… Apex One 14.0.0.14002 / 14.0.14492+ Fix from $1,9502025-06-17 HIGH 7.8 CVE-2025-49157 A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected in… Apex One 14.0.0.14002 / 14.0.14492+ Fix from $1,9502025-06-17 MEDIUM 5.5 CVE-2025-0913 os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, O… Go 1.23.10 / 1.24.4+ Fix from $1,6002025-06-11 HIGH 7.8 CVE-2025-33075 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 HIGH 7.3 CVE-2025-32721 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21034 / 10.0.14393.8148+ Fix from $1,9502025-06-10 HIGH 7.3 CVE-2025-5474 2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges … Syncbackfree Mitigation only Fix from $1,9502025-06-06 HIGH 7.8 CVE-2025-36564 Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially… Encryption 11.10.2+ Fix from $1,9502025-06-03