Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.8 CVE-2023-32163 Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o… Driver Mitigation only Fix from $1,9502023-09-06 HIGH 7.8 CVE-2022-46869 Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Of… Cyber Protect Home Office 40278+ Fix from $1,9502023-08-31 HIGH 7.5 CVE-2023-34723 An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf. La5570 Firmware No fix yet Fix from $1,9502023-08-25 HIGH 7.8 CVE-2019-13689 Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a… Chrome 75.0.3770.80+ Fix from $1,9502023-08-25 MEDIUM 6.5 CVE-2023-40028EPSS 68% Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows authenticated users to upload… Ghost 5.59.1+ Fix from $1,6002023-08-15 HIGH 7.8 CVE-2023-38175 Microsoft Windows Defender Elevation of Privilege Vulnerability Windows Defender 1.1.23060.3001+ Fix from $1,9502023-08-08 CRITICAL 9.8 CVE-2023-36903 Windows System Assessment Tool Elevation of Privilege Vulnerability Windows 10 10.0.10240.20107 / 10.0.14393.6167+ Fix from $2,3002023-08-08 HIGH 7.5 CVE-2022-48579 UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains. Unrar 6.2.3+ Fix from $1,9502023-08-07 CRITICAL 9.1 CVE-2023-39107 An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-… Nomachine 8.8.1+ Fix from $2,3002023-08-04 MEDIUM 6.5 CVE-2023-4052 The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively… Firefox 115.1 / 116.0+ Fix from $1,6002023-08-01 MEDIUM 6.5 CVE-2023-4053 A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This co… Firefox 116.0+ Fix from $1,6002023-08-01 HIGH 7.8 CVE-2023-36874 KEVEPSS 43% Windows Error Reporting Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20048 / 10.0.14393.6085+ Fix from $1,9502023-07-11 HIGH 7.1 CVE-2023-35347 Microsoft Install Service Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19041.3208 / 10.0.19045.3208+ Fix from $1,9502023-07-11 HIGH 7.8 CVE-2023-35353 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Windows 10 1607 10.0.14393.6085 / 10.0.17763.4645+ Fix from $1,9502023-07-11 HIGH 7.8 CVE-2023-35342 Windows Image Acquisition Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20048 / 10.0.14393.6085+ Fix from $1,9502023-07-11 HIGH 7.8 CVE-2023-35320 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability Windows 10 1607 10.0.14393.6085 / 10.0.17763.4645+ Fix from $1,9502023-07-11 HIGH 7.8 CVE-2023-33148 Microsoft Office Elevation of Privilege Vulnerability 365 Apps Patch available Fix from $1,9502023-07-11 HIGH 7.8 CVE-2023-32053 Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.20048 / 10.0.14393.6085+ Fix from $1,9502023-07-11 CRITICAL 9.8 CVE-2023-32056 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability Windows 10 1809 10.0.17763.4645 / 10.0.19041.3208+ Fix from $2,3002023-07-11 MEDIUM 6.5 CVE-2023-37206 Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulne… Firefox 115.0+ Fix from $1,6002023-07-05 HIGH 7.1 CVE-2023-27469 Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lack… Anti Exploit after 4.4.0.220 Fix from $1,9502023-06-30 MEDIUM 5.5 CVE-2023-32556 A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive informa… Apex One 14.0.12105+ Fix from $1,6002023-06-26 HIGH 7.3 CVE-2023-28065 Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vul… Alienware Update 4.9.0+ Fix from $1,9502023-06-23 HIGH 7.1 CVE-2023-28071 Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Poin… Alienware Update 4.9.0+ Fix from $1,9502023-06-23 HIGH 7.8 CVE-2023-32012 Windows Container Manager Service Elevation of Privilege Vulnerability Windows 10 21h2 10.0.19044.3087 / 10.0.19045.3087+ Fix from $1,9502023-06-14 HIGH 8.1 CVE-2023-29351 Windows Group Policy Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19983 / 10.0.14393.5989+ Fix from $1,9502023-06-14 HIGH 7.8 CVE-2023-33865 RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership. Renderdoc 1.27+ Fix from $1,9502023-06-07 HIGH 7.8 CVE-2023-2939 Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to perform privilege escalation… Chrome 114.0.5735.90+ Fix from $1,9502023-05-30 HIGH 8.8 CVE-2023-33245 Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that… Minecraft after 1.19 Fix from $1,9502023-05-30 MEDIUM 6.5 CVE-2023-34204 imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, a… Imapsync after 2.229 Fix from $1,6002023-05-30