Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.0
CVE-2026-12391
An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma…
No fix yet
HIGH 7.5
CVE-2026-61371
Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink targ…
Mitigation only
HIGH 8.8
CVE-2026-54572
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclon…
Rclone
1.74.4+
CRITICAL 9.1
CVE-2026-53486
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di…
Mitigation only
MEDIUM 5.5
CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
.net
8.0.29 / 9.0.18+
HIGH 7.8
CVE-2026-50469
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges l…
Windows 10 1809
10.0.17763.9020 / 10.0.19044.7548+
HIGH 8.8
CVE-2026-50438
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.22.1.0+
HIGH 7.8
CVE-2026-58636
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.21.6.0+
HIGH 7.3
CVE-2026-50364
Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.
Windows 10 21h2
10.0.19044.7548 / 10.0.19045.7548+
HIGH 7.8
CVE-2026-49791
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to e…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
MEDIUM 5.5
CVE-2026-49180
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.8
CVE-2026-49176
Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
HIGH 7.7
CVE-2026-15392
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location.
The complete_table_name method buil…
Mitigation only
HIGH 7.0
CVE-2026-6851
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and…
Internet Security
27.0.58.315+
MEDIUM 6.3
CVE-2026-15629
A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesy…
Mitigation only
MEDIUM 5.3
CVE-2026-15621
A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of…
No fix yet
MEDIUM 6.6
CVE-2026-62239
FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hoppe…
Patch available
HIGH 7.1
CVE-2026-62189
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform act…
Openclaw
2026.6.9+
MEDIUM 5.5
CVE-2026-15681
AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service cond…
Anydesk
Mitigation only
MEDIUM 5.5
CVE-2026-15682
AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service c…
Anydesk
Mitigation only
HIGH 7.3
CVE-2026-15684
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o…
Mitigation only
MEDIUM 5.3
CVE-2026-61858
ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attac…
Imagemagick
6.9.13-51 / 7.1.2-26+
MEDIUM 5.5
CVE-2026-39243
decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When process…
Decompress
after 4.2.1
HIGH 7.5
CVE-2026-39246
decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.link…
Decompress
after 4.2.1
MEDIUM 5.5
CVE-2026-58198
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predicta…
Patch available
HIGH 8.7
CVE-2026-14891
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host…
Mitigation only
MEDIUM 6.3
CVE-2026-55668
File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in s…
Patch available
MEDIUM 6.5
CVE-2026-14904
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual deskt…
Mitigation only
CRITICAL 9.6
CVE-2026-57571
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w…
Crawl4ai
0.9.0+
MEDIUM 5.5
CVE-2026-50135
Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat …
Hugo
0.161.1+