Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2026-27748
Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged…
Internet Security
1.1.114.3113+
HIGH 7.8
CVE-2026-27905
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.36, the safe_extract_tarfile(…
Bentoml
1.4.36+
HIGH 7.8
CVE-2026-25906
Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged at…
Optimizer
6.3.1.0+
HIGH 7.1
CVE-2025-66680
An issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files via a craf…
Wise Force Deleter
after 1.5.7.59
HIGH 8.4
CVE-2025-48582
In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an intent redirect. This could l…
Android
Mitigation only
HIGH 7.1
CVE-2026-27967
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `edit_file`). It allows reading…
Zed
0.225.9+
HIGH 7.4
CVE-2025-63946
A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute progr…
Pcmanager
after 17.10.28554.205
HIGH 7.4
CVE-2025-63945
A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs …
Ioa
210.9.28693.62001+
MEDIUM 5.5
CVE-2026-2490
RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose …
Patch available
HIGH 7.8
CVE-2026-2627
A security flaw has been discovered in Softland FBackup up to 9.9. This impacts an unknown function in the library C:\Program Files\Common Files\micr…
No fix yet
HIGH 8.5
CVE-2026-26225
Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones, contains a local privilege e…
Mitigation only
HIGH 7.8
CVE-2026-20610
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
macOS
26.3+
CRITICAL 9.8
CVE-2025-66277
A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerab…
Qts
Mitigation only
HIGH 7.0
CVE-2026-21517
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.
Windows App
11.3.2+
HIGH 7.1
CVE-2025-62676
An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7…
Forticlient
7.2.13 / 7.4.5+
HIGH 7.8
CVE-2025-15310
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
Endpoint Configuration Toolset Solution
1.40.37 / 3.17.10195+
HIGH 7.1
CVE-2025-15313
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
Euss
1.17.41 / 1.18.28+
HIGH 8.1
CVE-2025-15314
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
End User Cx
1.4.1175 / 1.6.926+
HIGH 7.8
CVE-2025-15319
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
Patch Endpoint Tools
3.17.10207 / 10.1.50+
MEDIUM 6.0
CVE-2025-15318
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
End User Notifications
1.18.10079 / 10.0.14+
MEDIUM 6.6
CVE-2026-21419
Dell Display and Peripheral Manager (Windows) versions prior to 2.2 contain an Improper Link Resolution Before File Access ('Link Following') vulnera…
Mitigation only
MEDIUM 6.6
CVE-2025-15324
Tanium addressed a documentation issue in Engage.
Engage
1.3.37 / 1.6.193+
MEDIUM 5.0
CVE-2025-15328
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
Enforce
2.7.314 / 2.8.544+
HIGH 7.8
CVE-2026-24884
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring…
Compressing
1.10.4+
MEDIUM 6.1
CVE-2025-69429
The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to leak or t…
Cd3510 Firmware
after 1.9.12
MEDIUM 6.1
CVE-2025-69430
An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), DM3 (vers…
Dm2 Firmware
after 1.9.12
MEDIUM 6.1
CVE-2025-69431
The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create a symbolic…
Q2c Firmware
after 1.1.0210050
MEDIUM 6.3
CVE-2025-15541
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files…
Vx800v Firmware
800.0.11+
HIGH 7.1
CVE-2026-23563
Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before ve…
Digital Employee Experience
26.1+
HIGH 8.2
CVE-2026-24842
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path res…
Tar
7.5.7+