Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
HIGH 7.8 CVE-2026-41091 KEVEPSS 10% Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. Malware Protection Engine 1.1.26040.8+ Fix from $1,9502026-05-20 MEDIUM 6.3 CVE-2026-43619 Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unli… Rsync after 3.4.2 Fix from $1,6002026-05-20 MEDIUM 5.3 CVE-2026-34883 An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability a… Mitigation only Fix from $1,6002026-05-19 HIGH 7.4 CVE-2026-45539 Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumer… No fix yet Fix from $1,9502026-05-15 HIGH 7.8 CVE-2026-44471 gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide,… Gix Fs 0.21.1+ Fix from $1,9502026-05-13 HIGH 7.5 CVE-2025-27850 The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is u… Empirbus Wireless Display Unit Firmware Mitigation only Fix from $1,9502026-05-13 HIGH 8.5 CVE-2026-43998 vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing s… Vm2 No fix yet Fix from $1,9502026-05-13 HIGH 7.8 CVE-2026-44470 The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the Cowo… Claude Desktop 1.3834.0+ Fix from $1,9502026-05-13 MEDIUM 6.0 CVE-2026-6959 HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user thro… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.0 CVE-2026-8052 HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user throug… Mitigation only Fix from $1,6002026-05-12 MEDIUM 5.0 CVE-2026-41610 Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass … Visual Studio Code 1.119.1+ Fix from $1,6002026-05-12 HIGH 8.5 CVE-2026-43989 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age… Patch available Fix from $1,9502026-05-12 HIGH 8.8 CVE-2021-47949 CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by expl… No fix yet Fix from $1,9502026-05-10 HIGH 7.5 CVE-2026-42574 apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk coul… Patch available Fix from $1,9502026-05-09 HIGH 7.5 CVE-2026-44340 PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack… Praisonai 4.6.37+ Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-39819 The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to t… Go 1.25.10 / 1.26.3+ Fix from $1,6002026-05-07 HIGH 7.0 CVE-2026-7832 A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The m… Mitigation only Fix from $1,9502026-05-05 HIGH 7.5 CVE-2026-41882 In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-i… Intellij Idea Mitigation only Fix from $1,9502026-04-30 HIGH 7.1 CVE-2026-27105 Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A… Dell\/alienware Purchased Apps 1.1.31.0+ Fix from $1,9502026-04-29 HIGH 8.8 CVE-2026-5161 Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About … Mitigation only Fix from $1,9502026-04-29 CRITICAL 9.6 CVE-2026-41397 OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du… Openclaw 2026.3.31+ Fix from $2,3002026-04-28 HIGH 8.1 CVE-2026-41364 OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files.… Openclaw 2026.3.31+ Fix from $1,9502026-04-28 MEDIUM 6.7 CVE-2026-40977 When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one fi… Spring Boot 2.7.33 / 3.3.19+ Fix from $1,6002026-04-28 HIGH 8.4 CVE-2026-41433 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java … Opentelemetry Ebpf Instrumentation 0.8.0+ Fix from $1,9502026-04-24 HIGH 7.8 CVE-2026-6941 radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the… Radare2 6.1.4+ Fix from $1,9502026-04-23 HIGH 7.4 CVE-2026-33694 This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condit… Mitigation only Fix from $1,9502026-04-23 HIGH 7.5 CVE-2026-41231 Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supp… Froxlor 2.3.6+ Fix from $1,9502026-04-23 MEDIUM 6.6 CVE-2026-35365 The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of… Coreutils 0.7.0+ Fix from $1,6002026-04-22 HIGH 7.7 CVE-2026-35349 A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check … Coreutils 0.7.0+ Fix from $1,9502026-04-22 MEDIUM 5.3 CVE-2026-35345 A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. U… Coreutils No fix yet Fix from $1,6002026-04-22