Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.0 CVE-2024-25953 Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged atta… Powerscale Onefs 9.5.0.8 / 9.7.0.2+ Fix from $1,6002024-03-28 HIGH 7.9 CVE-2024-29188 WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx`… Patch available Fix from $1,9502024-03-24 HIGH 8.8 CVE-2024-28916 Xbox Gaming Services Elevation of Privilege Vulnerability Xbox Gaming Services 19.87.13001.0+ Fix from $1,9502024-03-21 HIGH 8.6 CVE-2024-1753 A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build co… Mitigation only Fix from $1,9502024-03-18 HIGH 7.8 CVE-2024-26199 Microsoft Office Elevation of Privilege Vulnerability 365 Apps No fix yet Fix from $1,9502024-03-12 HIGH 7.0 CVE-2024-21432 Windows Update Stack Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20526 / 10.0.14393.6796+ Fix from $1,9502024-03-12 MEDIUM 5.5 CVE-2024-23285 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to prote… macOS 14.4+ Fix from $1,6002024-03-08 HIGH 7.1 CVE-2024-0068 Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows File Manipulation.This issue af… Workforce Access 8.7.1+ Fix from $1,9502024-02-29 HIGH 7.8 CVE-2023-42942 This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, iOS 16.7.2 and iPadOS… Ipad Os 10.1 / 13.6.1+ Fix from $1,9502024-02-21 MEDIUM 5.3 CVE-2024-21397 Microsoft Azure File Sync Elevation of Privilege Vulnerability Azure File Sync 16.2.0.0+ Fix from $1,6002024-02-13 HIGH 7.3 CVE-2024-21329 Azure Connected Machine Agent Elevation of Privilege Vulnerability Azure Connected Machine Agent 1.38+ Fix from $1,9502024-02-13 HIGH 7.5 CVE-2024-1329 HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad c… Nomad 1.5.14 / 1.6.7+ Fix from $1,9502024-02-08 MEDIUM 6.6 CVE-2023-32474 Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user c… Display Manager 2.1.1.21+ Fix from $1,6002024-02-06 HIGH 7.1 CVE-2023-32454 DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user c… Update Package Framework after 4.9.4.36 Fix from $1,9502024-02-06 CRITICAL 9.6 CVE-2023-52138 Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged t… Engrampa 1.26.2+ Fix from $2,3002024-02-05 MEDIUM 5.3 CVE-2023-7216 A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a… Enterprise Linux No fix yet Fix from $1,6002024-02-05 HIGH 7.8 CVE-2023-52090 A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. … Apex One 14.0.12849+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-52091 An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installat… Apex One 14.0.12849+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-52092 A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. … Apex One 14.0.12849+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-52094 An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary fo… Apex One 14.0.12849+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-52338 A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a l… Deep Security Mitigation only Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-47192 An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.… Apex One 14.0.12737+ Fix from $1,9502024-01-23 HIGH 7.8 CVE-2023-6335 Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on Windows allows User-Controlled Filename.This… Workforce Access 8.7+ Fix from $1,9502024-01-16 HIGH 7.8 CVE-2023-6336 Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This i… Workforce Access 8.7+ Fix from $1,9502024-01-16 HIGH 7.8 CVE-2023-42137 PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by us… Paydroid after 8.1.0_sagittarius_11.1.50_20230614 Fix from $1,9502024-01-15 HIGH 7.8 CVE-2023-31003 IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1)… Security Verify Access 10.0.0.7+ Fix from $1,9502024-01-11 HIGH 7.8 CVE-2024-20656 Visual Studio Elevation of Privilege Vulnerability Visual Studio 15.9.59 / 16.11.33+ Fix from $1,9502024-01-09 HIGH 7.8 CVE-2024-0206 A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to pot… Anti Malware Engine Mitigation only Fix from $1,9502024-01-09 MEDIUM 5.5 CVE-2023-51654 Improper link resolution before file access ('Link Following') issue exists in iPrint&Scan Desktop for Windows versions 11.0.0 and earlier. A symlink… Iprint\&scan after 11.0.0 Fix from $1,6002023-12-26 HIGH 8.8 CVE-2023-28872 Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic li… Secure Enterprise Client 13.10+ Fix from $1,9502023-12-25