Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.8 CVE-2023-27529 Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tric… Tablet Driver Installer 6.4.2-1+ Fix from $1,9502023-05-25 HIGH 7.8 CVE-2023-29343 SysInternals Sysmon for Windows Elevation of Privilege Vulnerability Windows Sysmon 14.16+ Fix from $1,9502023-05-09 HIGH 7.1 CVE-2022-34292 Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by c… Desktop 4.6.0+ Fix from $1,9502023-04-27 MEDIUM 6.3 CVE-2022-38730 Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling t… Desktop 4.6.0+ Fix from $1,6002023-04-27 HIGH 7.1 CVE-2022-31647 Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFo… Desktop 4.6.0+ Fix from $1,9502023-04-27 MEDIUM 6.3 CVE-2023-28141 An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary … Cloud Agent 4.8.0.31+ Fix from $1,6002023-04-18 MEDIUM 6.8 CVE-2023-28972 An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to … Junos Mitigation only Fix from $1,6002023-04-17 HIGH 7.1 CVE-2023-28222 Windows Kernel Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19869 / 10.0.14393.5850+ Fix from $1,9502023-04-11 HIGH 7.3 CVE-2022-38604 Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability. Driver No fix yet Fix from $1,9502023-04-11 MEDIUM 5.9 CVE-2022-43293 Wacom Driver 6.3.46-1 for Windows was discovered to contain an arbitrary file write vulnerability via the component \Wacom\Wacom_Tablet.exe. Driver No fix yet Fix from $1,6002023-04-11 HIGH 7.8 CVE-2023-0652 Due to a hardlink created in the ProgramData folder during the repair process of the software, the installer (MSI) of WARP Client for Windows (<= 202… Warp 2023.3.381.0+ Fix from $1,9502023-04-06 HIGH 7.8 CVE-2023-1412 An unprivileged (non-admin) user can exploit an Improper Access Control vulnerability in the Cloudflare WARP Client for Windows (<= 2022.12.582.0) to… Warp 2023.3.381.0+ Fix from $1,9502023-04-05 HIGH 7.8 CVE-2023-25940 Dell PowerScale OneFS version 9.5.0.0 contains improper link resolution before file access vulnerability in isi_gather_info. A high privileged local … Emc Powerscale Onefs Patch available Fix from $1,9502023-04-04 HIGH 7.5 CVE-2022-47188 There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the default credentials, could u… Cs141 Firmware 2.06+ Fix from $1,9502023-03-31 HIGH 7.8 CVE-2023-28642 runc is a CLI tool for spawning and running containers according to the OCI specification. It was found that AppArmor can be bypassed when `/proc` in… Runc 1.1.5+ Fix from $1,9502023-03-29 HIGH 7.8 CVE-2023-28892 Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in whic… Adwcleaner after 8.4.0 Fix from $1,9502023-03-29 HIGH 7.8 CVE-2023-26088 In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can … Malwarebytes 4.5.23+ Fix from $1,9502023-03-23 HIGH 7.8 CVE-2023-1314 A vulnerability has been discovered in cloudflared's installer (<= 2023.3.0) for Windows 32-bits devices that allows a local attacker with no adminis… Cloudflared 2023.3.1+ Fix from $1,9502023-03-21 HIGH 7.8 CVE-2023-24930 Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability Onedrive 23.020.0125.0002+ Fix from $1,9502023-03-14 MEDIUM 5.5 CVE-2023-24577 McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could en… Total Protection 16.0.50+ Fix from $1,6002023-03-13 HIGH 7.8 CVE-2023-25145 A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to escalate privileges on affected… Apex One 14.0.11960+ Fix from $1,9502023-03-10 HIGH 7.8 CVE-2023-25146 A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the origina… Apex One 14.0.11960+ Fix from $1,9502023-03-10 HIGH 7.8 CVE-2023-25148 A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specifi… Apex One 14.0.11960+ Fix from $1,9502023-03-10 MEDIUM 6.8 CVE-2023-27850 NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrar… Rax30 Firmware 1.0.10.94+ Fix from $1,6002023-03-10 MEDIUM 5.5 CVE-2022-22582EPSS 18% A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Securit… Mac Os X 11.6.5 / 12.3+ Fix from $1,6002023-02-27 HIGH 7.8 CVE-2022-45697 Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory. Razer Central 7.8.0.381+ Fix from $1,9502023-02-27 MEDIUM 6.3 CVE-2023-23558 In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode… Eternal Terminal Patch available Fix from $1,6002023-02-16 MEDIUM 5.6 CVE-2023-21567 Visual Studio Denial of Service Vulnerability Visual Studio 2017 15.9.52 / 16.11.24+ Fix from $1,6002023-02-14 MEDIUM 5.5 CVE-2023-22490 Git is a revision control system. Using a specially-crafted repository, Git prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7,… Git 2.30.8 / 2.31.7+ Fix from $1,6002023-02-14 MEDIUM 5.0 CVE-2023-21722 .NET Framework Denial of Service Vulnerability .net Framework Patch available Fix from $1,6002023-02-14