Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-41091 KEVEPSS 10%
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Malware Protection Engine
1.1.26040.8+
MEDIUM 6.3
CVE-2026-43619
Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod, lchown, utimes, rename, unli…
Rsync
after 3.4.2
MEDIUM 5.3
CVE-2026-34883
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability a…
Mitigation only
HIGH 7.4
CVE-2026-45539
Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumer…
No fix yet
HIGH 7.8
CVE-2026-44471
gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide,…
Gix Fs
0.21.1+
HIGH 7.5
CVE-2025-27850
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is u…
Empirbus Wireless Display Unit Firmware
Mitigation only
HIGH 8.5
CVE-2026-43998
vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing s…
Vm2
No fix yet
HIGH 7.8
CVE-2026-44470
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the Cowo…
Claude Desktop
1.3834.0+
MEDIUM 6.0
CVE-2026-6959
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user thro…
Mitigation only
MEDIUM 6.0
CVE-2026-8052
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user throug…
Mitigation only
MEDIUM 5.0
CVE-2026-41610
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …
Visual Studio Code
1.119.1+
HIGH 8.5
CVE-2026-43989
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a filesystem path from the age…
Patch available
HIGH 8.8
CVE-2021-47949
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by expl…
No fix yet
HIGH 7.5
CVE-2026-42574
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk coul…
Patch available
HIGH 7.5
CVE-2026-44340
PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, recipe publish, and recipe unpack…
Praisonai
4.6.37+
MEDIUM 5.3
CVE-2026-39819
The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to t…
Go
1.25.10 / 1.26.3+
HIGH 7.0
CVE-2026-7832
A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The m…
Mitigation only
HIGH 7.5
CVE-2026-41882
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-i…
Intellij Idea
Mitigation only
HIGH 7.1
CVE-2026-27105
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A…
Dell\/alienware Purchased Apps
1.1.31.0+
HIGH 8.8
CVE-2026-5161
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About …
Mitigation only
CRITICAL 9.6
CVE-2026-41397
OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation du…
Openclaw
2026.3.31+
HIGH 8.1
CVE-2026-41364
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files.…
Openclaw
2026.3.31+
MEDIUM 6.7
CVE-2026-40977
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one fi…
Spring Boot
2.7.33 / 3.3.19+
HIGH 8.4
CVE-2026-41433
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java …
Opentelemetry Ebpf Instrumentation
0.8.0+
HIGH 7.8
CVE-2026-6941
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…
Radare2
6.1.4+
HIGH 7.4
CVE-2026-33694
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condit…
Mitigation only
HIGH 7.5
CVE-2026-41231
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supp…
Froxlor
2.3.6+
MEDIUM 6.6
CVE-2026-35365
The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across filesystem boundaries. Instead of…
Coreutils
0.7.0+
HIGH 7.7
CVE-2026-35349
A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementation uses a path-string check …
Coreutils
0.7.0+
MEDIUM 5.3
CVE-2026-35345
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. U…
Coreutils
No fix yet