Vulnerability index

Browse CVEs

1,372 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.1 CVE-2022-21997 Windows Print Spooler Elevation of Privilege Vulnerability Windows 10 No fix yet Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-21999 KEVEPSS 42% Windows Print Spooler Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19204 / 10.0.14393.4946+ Fix from $1,9502022-02-09 HIGH 7.8 CVE-2021-23521 This affects the package juce-framework/JUCE before 6.1.5. This vulnerability is triggered when a malicious archive is crafted with an entry containi… Juce 6.1.5+ Fix from $1,9502022-01-31 HIGH 7.8 CVE-2022-21944 A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows loca… Factory Watchman after 4.9.1 Fix from $1,9502022-01-26 HIGH 7.1 CVE-2022-0012 An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables a lo… Cortex Xdr Agent 5.0.12 / 6.1.9+ Fix from $1,9502022-01-12 HIGH 7.0 CVE-2022-21919 KEV Windows User Profile Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19177 / 10.0.14393.4886+ Fix from $1,9502022-01-11 HIGH 7.8 CVE-2022-21895 Windows User Profile Service Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502022-01-11 HIGH 7.8 CVE-2022-21838 Windows Cleanup Manager Elevation of Privilege Vulnerability Windows 10 Mitigation only Fix from $1,9502022-01-11 HIGH 7.1 CVE-2021-45442 A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite… Apex One Patch available Fix from $1,9502022-01-10 HIGH 7.8 CVE-2021-45231 A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1… Apex One Patch available Fix from $1,9502022-01-10 HIGH 7.1 CVE-2021-44024 A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 an… Apex One Patch available Fix from $1,9502022-01-10 MEDIUM 6.8 CVE-2021-20153 Trendnet AC2600 TEW-827DRU version 2.08B01 contains a symlink vulnerability in the bittorrent functionality. If enabled, the bittorrent functionality… Tew 827dru Firmware Mitigation only Fix from $1,6002021-12-30 HIGH 8.8 CVE-2021-23772 This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names … Iris after 12.1.8 Fix from $1,9502021-12-24 HIGH 7.1 CVE-2021-44023 A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abu… Antivirus\+ Security 2021 after 17.0 Fix from $1,9502021-12-16 HIGH 7.3 CVE-2021-43237 Windows Setup Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-12-15 HIGH 7.8 CVE-2021-43238 Windows Remote Access Elevation of Privilege Vulnerability Windows 10 Patch available Fix from $1,9502021-12-15 MEDIUM 5.0 CVE-2021-42297 Windows 10 Update Assistant Elevation of Privilege Vulnerability Windows 10 Update Assistant Patch available Fix from $1,6002021-11-24 HIGH 7.8 CVE-2021-44038 An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-o… Quagga after 1.2.4 Fix from $1,9502021-11-19 HIGH 7.1 CVE-2021-41057 In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. Codemeter Runtime 7.30a / 8.0+ Fix from $1,9502021-11-14 MEDIUM 5.5 CVE-2021-41379 KEVEPSS 20% Windows Installer Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19119 / 10.0.14393.4770+ Fix from $1,6002021-11-10 MEDIUM 6.1 CVE-2021-3641 Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoint Security Tools for Windows… Gravityzone after 7.1.2.33 Fix from $1,6002021-11-09 HIGH 8.1 CVE-2021-21686 File path filters in the agent-to-controller security subsystem of Jenkins 2.318 and earlier, LTS 2.303.2 and earlier do not canonicalize paths, allo… Jenkins 2.303.3 / 2.319+ Fix from $1,9502021-11-04 CRITICAL 9.8 CVE-2021-21691 Creating symbolic links is possible without the 'symlink' agent-to-controller access control permission in Jenkins 2.318 and earlier, LTS 2.303.2 and… Jenkins 2.303.3 / 2.319+ Fix from $2,3002021-11-04 HIGH 8.8 CVE-2021-21695 FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Jenkins 2.318 and earlier, LTS … Jenkins 2.303.3 / 2.319+ Fix from $1,9502021-11-04 HIGH 7.5 CVE-2021-22488 There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tam… Emui Mitigation only Fix from $1,9502021-10-28 HIGH 7.8 CVE-2021-37969 Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege… Chrome 94.0.4606.54+ Fix from $1,9502021-10-08 HIGH 7.1 CVE-2021-36286 Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be … Supportassist Client Consumer after 3.9.13.0 Fix from $1,9502021-09-28 HIGH 7.8 CVE-2021-34408 The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user duri… Meetings 5.3.2+ Fix from $1,9502021-09-27 HIGH 7.1 CVE-2021-1612 A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system… Sd Wan 17.3.4+ Fix from $1,9502021-09-23 HIGH 7.8 CVE-2021-31843 Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to ac… Endpoint Security 10.7.0+ Fix from $1,9502021-09-17