Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2025-46293
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user d…
macOS
15.4+
MEDIUM 6.1
CVE-2026-45384
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary …
Mitigation only
CRITICAL 9.6
CVE-2026-53476
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal…
Assisted Migration Agent
2026-06-07+
MEDIUM 6.5
CVE-2026-11853
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts …
Mitigation only
HIGH 7.3
CVE-2026-11837
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() inst…
Mitigation only
HIGH 7.8
CVE-2026-50511
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Pc Manager
3.21.6.0+
MEDIUM 6.3
CVE-2026-44275
Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A…
Mitigation only
HIGH 7.8
CVE-2026-45586
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevat…
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 5.5
CVE-2026-45491
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
.net
8.0.28 / 9.0.17+
HIGH 7.8
CVE-2026-42989
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9234 / 10.0.17763.8880+
MEDIUM 6.0
CVE-2026-28262
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile…
Mitigation only
MEDIUM 6.5
CVE-2026-11322
Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks …
Patch available
HIGH 8.8
CVE-2026-41236
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path…
Mitigation only
MEDIUM 5.1
CVE-2026-42795
Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.
…
Patch available
HIGH 7.1
CVE-2026-49135
CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or ta…
Patch available
MEDIUM 6.5
CVE-2026-40861
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (rea…
Airflow
3.2.2+
MEDIUM 5.0
CVE-2026-6892
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit …
Mitigation only
MEDIUM 5.0
CVE-2026-6891
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login priv…
Mitigation only
CRITICAL 9.9
CVE-2026-44881
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber…
Portainer
2.33.8 / 2.39.2+
HIGH 7.7
CVE-2026-9804
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerabili…
Mitigation only
HIGH 7.9
CVE-2026-44711
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files ena…
Mitigation only
HIGH 7.5
CVE-2026-48921
Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers …
Pipeline\
798.v5cc688825312+
MEDIUM 5.5
CVE-2026-48693
FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defau…
Fastnetmon
after 1.2.9
CRITICAL 9.9
CVE-2026-7374
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single na…
Mitigation only
CRITICAL 9.1
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() …
\
3.08+
HIGH 7.5
CVE-2026-42497
Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.
_make_special_file() pas…
\
3.08+
MEDIUM 5.5
CVE-2026-40610
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build pa…
Bentoml
1.4.39+
HIGH 7.8
CVE-2025-71212
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations.…
Apex One
14.0.0.14136 / 14.0.20315+
HIGH 8.1
CVE-2026-44051
An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite…
Mitigation only
HIGH 7.8
CVE-2026-42834
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
0.72.0.0+