Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.0
CVE-2024-25953
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged atta…
Powerscale Onefs
9.5.0.8 / 9.7.0.2+
HIGH 7.9
CVE-2024-29188
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx`…
Patch available
HIGH 8.8
CVE-2024-28916
Xbox Gaming Services Elevation of Privilege Vulnerability
Xbox Gaming Services
19.87.13001.0+
HIGH 8.6
CVE-2024-1753
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build co…
Mitigation only
HIGH 7.8
CVE-2024-26199
Microsoft Office Elevation of Privilege Vulnerability
365 Apps
No fix yet
HIGH 7.0
CVE-2024-21432
Windows Update Stack Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20526 / 10.0.14393.6796+
MEDIUM 5.5
CVE-2024-23285
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to prote…
macOS
14.4+
HIGH 7.1
CVE-2024-0068
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue af…
Workforce Access
8.7.1+
HIGH 7.8
CVE-2023-42942
This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS…
Ipad Os
10.1 / 13.6.1+
MEDIUM 5.3
CVE-2024-21397
Microsoft Azure File Sync Elevation of Privilege Vulnerability
Azure File Sync
16.2.0.0+
HIGH 7.3
CVE-2024-21329
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Azure Connected Machine Agent
1.38+
HIGH 7.5
CVE-2024-1329
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad c…
Nomad
1.5.14 / 1.6.7+
MEDIUM 6.6
CVE-2023-32474
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user c…
Display Manager
2.1.1.21+
HIGH 7.1
CVE-2023-32454
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user c…
Update Package Framework
after 4.9.4.36
CRITICAL 9.6
CVE-2023-52138
Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged t…
Engrampa
1.26.2+
MEDIUM 5.3
CVE-2023-7216
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…
Enterprise Linux
No fix yet
HIGH 7.8
CVE-2023-52090
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.
…
Apex One
14.0.12849+
HIGH 7.8
CVE-2023-52091
An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installat…
Apex One
14.0.12849+
HIGH 7.8
CVE-2023-52092
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.
…
Apex One
14.0.12849+
HIGH 7.8
CVE-2023-52094
An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary fo…
Apex One
14.0.12849+
HIGH 7.8
CVE-2023-52338
A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a l…
Deep Security
Mitigation only
HIGH 7.8
CVE-2023-47192
An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.…
Apex One
14.0.12737+
HIGH 7.8
CVE-2023-6335
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This…
Workforce Access
8.7+
HIGH 7.8
CVE-2023-6336
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This i…
Workforce Access
8.7+
HIGH 7.8
CVE-2023-42137
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by us…
Paydroid
after 8.1.0_sagittarius_11.1.50_20230614
HIGH 7.8
CVE-2023-31003
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)…
Security Verify Access
10.0.0.7+
HIGH 7.8
CVE-2024-20656
Visual Studio Elevation of Privilege Vulnerability
Visual Studio
15.9.59 / 16.11.33+
HIGH 7.8
CVE-2024-0206
A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to pot…
Anti Malware Engine
Mitigation only
MEDIUM 5.5
CVE-2023-51654
Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink…
Iprint\&scan
after 11.0.0
HIGH 8.8
CVE-2023-28872
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic li…
Secure Enterprise Client
13.10+