Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.0 CVE-2026-12391 An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma… No fix yet Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-61371 Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink targ… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-54572 Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclon… Rclone 1.74.4+ Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-53486 The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target di… Mitigation only Fix from $2,3002026-07-14 MEDIUM 5.5 CVE-2026-50526 Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. .net 8.0.29 / 9.0.18+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50469 Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges l… Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-50438 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.22.1.0+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58636 Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-50364 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49791 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to e… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-49180 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-49176 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.7 CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method buil… Mitigation only Fix from $1,9502026-07-14 HIGH 7.0 CVE-2026-6851 An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in Bitdefender Total Security and… Internet Security 27.0.58.315+ Fix from $1,9502026-07-14 MEDIUM 6.3 CVE-2026-15629 A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesy… Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-15621 A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of… No fix yet Fix from $1,6002026-07-14 MEDIUM 6.6 CVE-2026-62239 FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and_copy() function within hoppe… Patch available Fix from $1,6002026-07-13 HIGH 7.1 CVE-2026-62189 OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform act… Openclaw 2026.6.9+ Fix from $1,9502026-07-13 MEDIUM 5.5 CVE-2026-15681 AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service cond… Anydesk Mitigation only Fix from $1,6002026-07-13 MEDIUM 5.5 CVE-2026-15682 AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service c… Anydesk Mitigation only Fix from $1,6002026-07-13 HIGH 7.3 CVE-2026-15684 Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o… Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.3 CVE-2026-61858 ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attac… Imagemagick 6.9.13-51 / 7.1.2-26+ Fix from $1,6002026-07-11 MEDIUM 5.5 CVE-2026-39243 decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When process… Decompress after 4.2.1 Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-39246 decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.link… Decompress after 4.2.1 Fix from $1,9502026-07-09 MEDIUM 5.5 CVE-2026-58198 ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predicta… Patch available Fix from $1,6002026-07-09 HIGH 8.7 CVE-2026-14891 HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-55668 File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in s… Patch available Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-14904 AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual deskt… Mitigation only Fix from $1,6002026-07-07 CRITICAL 9.6 CVE-2026-57571 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 MEDIUM 5.5 CVE-2026-50135 Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat … Hugo 0.161.1+ Fix from $1,6002026-07-06