Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.8 CVE-2023-43116 A symbolic link following vulnerability in Buildkite Elastic CI for AWS versions prior to 6.7.1 and 5.22.5 allows the buildkite-agent user to change … Elastic Ci Stack 5.22.5 / 6.7.1+ Fix from $1,9502023-12-22 HIGH 7.8 CVE-2023-36391EPSS 7% Local Security Authority Subsystem Service Elevation of Privilege Vulnerability Windows 11 23h2 10.0.22631.2861+ Fix from $1,9502023-12-12 HIGH 7.8 CVE-2023-35633EPSS 9% Windows Kernel Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20345+ Fix from $1,9502023-12-12 HIGH 7.3 CVE-2023-35624 Azure Connected Machine Agent Elevation of Privilege Vulnerability Azure Connected Machine Agent 1.37+ Fix from $1,9502023-12-12 HIGH 8.1 CVE-2023-28868 Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbo… Secure Enterprise Client 12.22+ Fix from $1,9502023-12-09 MEDIUM 6.5 CVE-2023-28869 Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creat… Secure Enterprise Client 12.22+ Fix from $1,6002023-12-09 HIGH 7.3 CVE-2023-39246 Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation o… Endpoint Security Suite Enterprise 11.8.1+ Fix from $1,9502023-11-16 HIGH 7.8 CVE-2023-43590 Link following in Zoom Rooms for macOS before version 5.16.0 may allow an authenticated user to conduct an escalation of privilege via local access. Rooms 5.16.0+ Fix from $1,9502023-11-15 HIGH 7.8 CVE-2023-36705 Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20308 / 10.0.14393.6452+ Fix from $1,9502023-11-14 HIGH 7.1 CVE-2023-36399EPSS 8% Windows Storage Elevation of Privilege Vulnerability Windows 11 21h2 10.0.22000.2600 / 10.0.22621.2715+ Fix from $1,9502023-11-14 HIGH 7.0 CVE-2023-36394EPSS 7% Windows Search Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20308 / 10.0.14393.6452+ Fix from $1,9502023-11-14 HIGH 7.8 CVE-2023-36047 Windows Authentication Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.5122 / 10.0.19041.3693+ Fix from $1,9502023-11-14 HIGH 7.1 CVE-2023-36046 Windows Authentication Denial of Service Vulnerability Windows 11 21h2 10.0.22000.2600 / 10.0.22621.2715+ Fix from $1,9502023-11-14 HIGH 8.8 CVE-2023-6069 Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0. Froxlor 2.1.0+ Fix from $1,9502023-11-10 HIGH 7.1 CVE-2020-28407 In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file… Swtpm 0.4.2+ Fix from $1,9502023-11-03 HIGH 7.8 CVE-2023-5834 HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauth… Vagrant 2.4.0+ Fix from $1,9502023-10-27 HIGH 7.5 CVE-2018-17559 Due to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras. Tvip 10000 Firmware No fix yet Fix from $1,9502023-10-26 HIGH 7.5 CVE-2023-42844 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A… macOS 12.7.1 / 13.6.1+ Fix from $1,9502023-10-25 HIGH 8.1 CVE-2023-46654 Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of th… Cloudbees Cd after 1.1.32 Fix from $1,9502023-10-25 MEDIUM 6.5 CVE-2023-46655 Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the directory from which artifacts are published during… Cloudbees Cd after 1.1.32 Fix from $1,6002023-10-25 HIGH 7.3 CVE-2023-28797 Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace… Client Connector 4.1+ Fix from $1,9502023-10-23 HIGH 7.8 CVE-2023-36737 Azure Network Watcher VM Agent Elevation of Privilege Vulnerability Azure Network Watcher 1.4.2798.3+ Fix from $1,9502023-10-10 HIGH 7.8 CVE-2023-36711 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20232 / 10.0.14393.6351+ Fix from $1,9502023-10-10 HIGH 7.8 CVE-2023-36723 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.4974 / 10.0.19041.3570+ Fix from $1,9502023-10-10 HIGH 7.0 CVE-2023-36568 Microsoft Office Click-To-Run Elevation of Privilege Vulnerability 365 Apps Patch available Fix from $1,9502023-10-10 HIGH 8.4 CVE-2023-45159 1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junctio… Client Mitigation only Fix from $1,9502023-10-05 MEDIUM 5.5 CVE-2023-41968 This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.6, tvOS 17, macOS Monterey 12.7, watchOS 10, i… Ipados 10.0 / 12.7+ Fix from $1,6002023-09-27 HIGH 7.8 CVE-2023-32182 A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux … Leap No fix yet Fix from $1,9502023-09-19 CRITICAL 9.8 CVE-2023-36758 Visual Studio Elevation of Privilege Vulnerability Visual Studio 2022 after 17.7.4 Fix from $2,3002023-09-12 HIGH 8.8 CVE-2023-4759 Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic link present in a specially craf… Jgit 5.13.3.202401111512-r / 6.6.0.202305301015+ Fix from $1,9502023-09-12