Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.8 CVE-2026-61358 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker t… Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72694 A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can expl… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.1 CVE-2025-30240 The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic li… No fix yet Fix from $4,0002026-08-10 HIGH 7.8 CVE-2026-63622 A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.5 CVE-2026-71964 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated atta… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-70622 tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read … No fix yet Fix from $4,0002026-08-10 MEDIUM 5.5 CVE-2026-15059 Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. No fix yet Fix from $4,0002026-08-10 HIGH 8.8 CVE-2026-19429 Jenkins FilePath.untarFrom() does not validate symlink targets in extracted TAR archives, even in versions patched for CVE-2026-33001 and CVE-2026-70… No fix yet Fix from $4,9002026-08-10 HIGH 7.1 CVE-2026-71556 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, st… No fix yet Fix from $1,9502026-08-07 HIGH 8.7 CVE-2026-71476 Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache ex… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19008 A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandb… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.1 CVE-2026-20310 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen… No fix yet Fix from $2,3002026-08-05 HIGH 7.8 CVE-2026-12410 Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escala… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-40717 Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged atta… Monitor Driver No fix yet Fix from $1,9502026-08-03 MEDIUM 5.8 CVE-2026-67433 Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile c… No fix yet Fix from $1,6002026-07-29 HIGH 7.8 CVE-2026-13268 G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate p… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-13723 A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by expl… No fix yet Fix from $1,6002026-07-29 MEDIUM 5.5 CVE-2026-43765 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An a… macOS 14.8.8 / 15.7.8+ Fix from $1,6002026-07-27 CRITICAL 9.2 CVE-2026-12503 Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A6… No fix yet Fix from $2,3002026-07-24 MEDIUM 6.3 CVE-2026-16552 A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic … No fix yet Fix from $1,6002026-07-22 MEDIUM 5.5 CVE-2026-65065 Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The se… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.2 CVE-2026-64613 Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created … No fix yet Fix from $1,6002026-07-21 MEDIUM 6.1 CVE-2026-47121 Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents con… Sparkle 2.9.2+ Fix from $1,6002026-07-21 MEDIUM 6.3 CVE-2026-44509 Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fix… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-15788 BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cac… Buildkit 0.31.2+ Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-8170 The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links … No fix yet Fix from $1,9502026-07-20 MEDIUM 5.5 CVE-2026-58414 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using … Network Ai 5.12.2+ Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-16077 A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file astrbot/core/tools/computer_to… No fix yet Fix from $1,6002026-07-18 HIGH 7.1 CVE-2026-50163 oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relat… No fix yet Fix from $1,9502026-07-17 MEDIUM 5.9 CVE-2026-53535 Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a … No fix yet Fix from $1,6002026-07-16