Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.5 CVE-2024-12905 An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal").… Patch available Fix from $1,9502025-03-27 HIGH 7.8 CVE-2025-29795 Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges… Edge Update 1.3.195.45+ Fix from $1,9502025-03-23 HIGH 8.8 CVE-2024-12390 A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-pr… Gpt Academic No fix yet Fix from $1,9502025-03-20 HIGH 7.1 CVE-2024-12216 A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write… Mitigation only Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-10986 GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extra… Gpt Academic No fix yet Fix from $1,9502025-03-20 HIGH 7.8 CVE-2025-1683 Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivile… Platform 25.3+ Fix from $1,9502025-03-12 HIGH 7.1 CVE-2025-25008 Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. Windows Server 2016 10.0.14393.7876 / 10.0.17763.7009+ Fix from $1,9502025-03-11 HIGH 7.5 CVE-2025-25185 GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. A… Gpt Academic Patch available Fix from $1,9502025-03-03 HIGH 8.8 CVE-2024-45418 Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of priv… Meeting Software Development Kit 6.1.5+ Fix from $1,9502025-02-25 HIGH 7.8 CVE-2025-22480 Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access c… Supportassist Os Recovery 5.5.13.1+ Fix from $1,9502025-02-13 MEDIUM 5.6 CVE-2020-3432 A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to co… Anyconnect Secure Mobility Client 4.9.00086+ Fix from $1,6002025-02-12 HIGH 7.1 CVE-2025-21419 Windows Setup Files Cleanup Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 HIGH 7.8 CVE-2025-21420 Windows Disk Cleanup Tool Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 HIGH 7.1 CVE-2025-21391 KEV Windows Storage Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 HIGH 7.8 CVE-2025-21373 Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,9502025-02-11 HIGH 7.8 CVE-2025-21322 Microsoft PC Manager Elevation of Privilege Vulnerability Pc Manager 3.15.4.0+ Fix from $1,9502025-02-11 MEDIUM 6.0 CVE-2025-21347 Windows Deployment Services Denial of Service Vulnerability Windows 10 1507 10.0.10240.20915 / 10.0.14393.7785+ Fix from $1,6002025-02-11 MEDIUM 6.0 CVE-2025-21188 Azure Network Watcher VM Extension Elevation of Privilege Vulnerability Azure Network Watcher 1.4.3563.1+ Fix from $1,6002025-02-11 HIGH 7.8 CVE-2025-0413 Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to esca… Remote Application Server 19.4.3.2-25228 / 19.4.3-25221+ Fix from $1,9502025-02-05 MEDIUM 5.0 CVE-2025-0146 Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via … Meeting Software Development Kit 6.2.10+ Fix from $1,6002025-01-30 MEDIUM 5.5 CVE-2025-24103 This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. … macOS 13.7.3 / 14.7.3+ Fix from $1,6002025-01-27 MEDIUM 5.5 CVE-2025-24104 This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously … Ipados 17.7.4 / 18.3+ Fix from $1,6002025-01-27 CRITICAL 9.1 CVE-2025-0377 HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry. Go Slug 0.16.3+ Fix from $2,3002025-01-21 HIGH 7.2 CVE-2024-57728 KEVEPSS 7% SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted … Simplehelp 5.5.8+ Fix from $1,9502025-01-15 HIGH 7.3 CVE-2025-21331 Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,9502025-01-14 MEDIUM 5.5 CVE-2025-21274 Windows Event Tracing Denial of Service Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 HIGH 7.8 CVE-2024-52050 A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installatio… Apex One 14.0.14203 / 2019.13140+ Fix from $1,9502024-12-31 HIGH 7.3 CVE-2024-12753 Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affecte… Pdf Editor after 2024.3.0.26795 Fix from $1,9502024-12-30 HIGH 7.8 CVE-2024-13043 Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affe… Panda Dome Mitigation only Fix from $1,9502024-12-30 MEDIUM 5.5 CVE-2024-12754 AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected … Anydesk Mitigation only Fix from $1,6002024-12-30