Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-12905
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal").…
Patch available
HIGH 7.8
CVE-2025-29795
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges…
Edge Update
1.3.195.45+
HIGH 8.8
CVE-2024-12390
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-pr…
Gpt Academic
No fix yet
HIGH 7.1
CVE-2024-12216
A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write…
Mitigation only
HIGH 8.8
CVE-2024-10986
GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extra…
Gpt Academic
No fix yet
HIGH 7.8
CVE-2025-1683
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivile…
Platform
25.3+
HIGH 7.1
CVE-2025-25008
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
Windows Server 2016
10.0.14393.7876 / 10.0.17763.7009+
HIGH 7.5
CVE-2025-25185
GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. A…
Gpt Academic
Patch available
HIGH 8.8
CVE-2024-45418
Symlink following in the installer for some Zoom apps for macOS before version 6.1.5 may allow an authenticated user to conduct an escalation of priv…
Meeting Software Development Kit
6.1.5+
HIGH 7.8
CVE-2025-22480
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access c…
Supportassist Os Recovery
5.5.13.1+
MEDIUM 5.6
CVE-2020-3432
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to co…
Anyconnect Secure Mobility Client
4.9.00086+
HIGH 7.1
CVE-2025-21419
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.8
CVE-2025-21420
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.1
CVE-2025-21391 KEV
Windows Storage Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.8
CVE-2025-21373
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.8
CVE-2025-21322
Microsoft PC Manager Elevation of Privilege Vulnerability
Pc Manager
3.15.4.0+
MEDIUM 6.0
CVE-2025-21347
Windows Deployment Services Denial of Service Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
MEDIUM 6.0
CVE-2025-21188
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
Azure Network Watcher
1.4.3563.1+
HIGH 7.8
CVE-2025-0413
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability.
This vulnerability allows local attackers to esca…
Remote Application Server
19.4.3.2-25228 / 19.4.3-25221+
MEDIUM 5.0
CVE-2025-0146
Symlink following in the installer for Zoom Workplace App for macOS before 6.2.10 may allow an authenticated user to conduct a denial of service via …
Meeting Software Development Kit
6.2.10+
MEDIUM 5.5
CVE-2025-24103
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. …
macOS
13.7.3 / 14.7.3+
MEDIUM 5.5
CVE-2025-24104
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously …
Ipados
17.7.4 / 18.3+
CRITICAL 9.1
CVE-2025-0377
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
Go Slug
0.16.3+
HIGH 7.2
CVE-2024-57728 KEVEPSS 7%
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted …
Simplehelp
5.5.8+
HIGH 7.3
CVE-2025-21331
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
MEDIUM 5.5
CVE-2025-21274
Windows Event Tracing Denial of Service Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 7.8
CVE-2024-52050
A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installatio…
Apex One
14.0.14203 / 2019.13140+
HIGH 7.3
CVE-2024-12753
Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affecte…
Pdf Editor
after 2024.3.0.26795
HIGH 7.8
CVE-2024-13043
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affe…
Panda Dome
Mitigation only
MEDIUM 5.5
CVE-2024-12754
AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected …
Anydesk
Mitigation only