Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 5.5 CVE-2025-46293 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user d… macOS 15.4+ Fix from $1,6002026-06-11 MEDIUM 6.1 CVE-2026-45384 bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary … Mitigation only Fix from $1,6002026-06-10 CRITICAL 9.6 CVE-2026-53476 A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal… Assisted Migration Agent 2026-06-07+ Fix from $2,3002026-06-10 MEDIUM 6.5 CVE-2026-11853 Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts … Mitigation only Fix from $1,6002026-06-10 HIGH 7.3 CVE-2026-11837 A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() inst… Mitigation only Fix from $1,9502026-06-10 HIGH 7.8 CVE-2026-50511 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 MEDIUM 6.3 CVE-2026-44275 Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A… Mitigation only Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-45586 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 MEDIUM 5.5 CVE-2026-45491 Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. .net 8.0.28 / 9.0.17+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-42989 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 MEDIUM 6.0 CVE-2026-28262 Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privile… Mitigation only Fix from $1,6002026-06-09 MEDIUM 6.5 CVE-2026-11322 Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks … Patch available Fix from $1,6002026-06-04 HIGH 8.8 CVE-2026-41236 Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path… Mitigation only Fix from $1,9502026-06-04 MEDIUM 5.1 CVE-2026-42795 Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. … Patch available Fix from $1,6002026-06-02 HIGH 7.1 CVE-2026-49135 CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or ta… Patch available Fix from $1,9502026-06-01 MEDIUM 6.5 CVE-2026-40861 A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (rea… Airflow 3.2.2+ Fix from $1,6002026-06-01 MEDIUM 5.0 CVE-2026-6892 Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit … Mitigation only Fix from $1,6002026-05-29 MEDIUM 5.0 CVE-2026-6891 Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login priv… Mitigation only Fix from $1,6002026-05-29 CRITICAL 9.9 CVE-2026-44881 Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kuber… Portainer 2.33.8 / 2.39.2+ Fix from $2,3002026-05-28 HIGH 7.7 CVE-2026-9804 A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerabili… Mitigation only Fix from $1,9502026-05-28 HIGH 7.9 CVE-2026-44711 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files ena… Mitigation only Fix from $1,9502026-05-27 HIGH 7.5 CVE-2026-48921 Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers … Pipeline\ 798.v5cc688825312+ Fix from $1,9502026-05-27 MEDIUM 5.5 CVE-2026-48693 FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. The statistics file path defau… Fastnetmon after 1.2.9 Fix from $1,6002026-05-26 CRITICAL 9.9 CVE-2026-7374 A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single na… Mitigation only Fix from $2,3002026-05-26 CRITICAL 9.1 CVE-2026-42496 Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() … \ 3.08+ Fix from $2,3002026-05-26 HIGH 7.5 CVE-2026-42497 Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() pas… \ 3.08+ Fix from $1,9502026-05-26 MEDIUM 5.5 CVE-2026-40610 BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build pa… Bentoml 1.4.39+ Fix from $1,6002026-05-22 HIGH 7.8 CVE-2025-71212 A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations.… Apex One 14.0.0.14136 / 14.0.20315+ Fix from $1,9502026-05-21 HIGH 8.1 CVE-2026-44051 An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite… Mitigation only Fix from $1,9502026-05-21 HIGH 7.8 CVE-2026-42834 Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 0.72.0.0+ Fix from $1,9502026-05-20