Vulnerability index

Browse CVEs

1,369 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.5 CVE-2026-24056 pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads the… Pnpm 10.28.2+ Fix from $1,6002026-01-26 MEDIUM 6.8 CVE-2025-67124 A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an attacker to overwrite arbitrary f… Miniserve No fix yet Fix from $1,6002026-01-23 MEDIUM 6.8 CVE-2026-23893 openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running i… Opencryptoki Patch available Fix from $1,6002026-01-22 HIGH 7.1 CVE-2026-24046 Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlin… Patch available Fix from $1,9502026-01-21 MEDIUM 6.3 CVE-2026-24047 Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend an… Patch available Fix from $1,6002026-01-21 MEDIUM 5.5 CVE-2025-13154 An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to… Mitigation only Fix from $1,6002026-01-14 HIGH 7.8 CVE-2026-20941 Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges … Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,9502026-01-13 MEDIUM 5.3 CVE-2026-22701 filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock im… Filelock 3.20.3+ Fix from $1,6002026-01-10 HIGH 7.3 CVE-2025-12838 MSP360 Free Backup Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affec… Mitigation only Fix from $1,9502025-12-23 HIGH 7.8 CVE-2023-53973 Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy files to unauthorized system … Total Security No fix yet Fix from $1,9502025-12-22 MEDIUM 6.5 CVE-2025-68279 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf… Weblate 5.15.1+ Fix from $1,6002025-12-18 MEDIUM 6.5 CVE-2025-68146 filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows loca… Filelock 3.20.1+ Fix from $1,6002025-12-16 MEDIUM 6.2 CVE-2025-14693 A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads … Mitigation only Fix from $1,6002025-12-15 MEDIUM 5.5 CVE-2025-43461 This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user d… macOS 26.1+ Fix from $1,6002025-12-12 MEDIUM 5.5 CVE-2025-43381 This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to delete protected… macOS 26.1+ Fix from $1,6002025-12-12 HIGH 7.8 CVE-2025-7073 A local privilege escalation vulnerability in Bitdefender Total Security versions prior to 27.0.47.241 allows low-privileged attackers to elevate pri… Antivirus 7.9.20.515 / 27.0.47.241+ Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-66626 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions 3.6.13 and below and versio… Argo Workflows 3.6.14 / 3.7.5+ Fix from $1,9502025-12-09 MEDIUM 6.6 CVE-2025-46636 Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged… Encryption 11.12.1+ Fix from $1,6002025-12-09 HIGH 7.3 CVE-2025-46637 Dell Encryption, versions prior to 11.12.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A local maliciou… Encryption 11.12.1+ Fix from $1,9502025-12-09 HIGH 8.6 CVE-2025-67487 Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (s… Static Web Server after 2.40.0 Fix from $1,9502025-12-09 HIGH 7.7 CVE-2025-65843 Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application f… Aquarius No fix yet Fix from $1,9502025-12-03 HIGH 8.5 CVE-2025-34352 JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Windows Agent as NT AUTHORITY\S… Mitigation only Fix from $1,9502025-12-02 HIGH 7.8 CVE-2025-60710 KEV Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges … Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,9502025-11-11 MEDIUM 5.5 CVE-2025-59510 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to d… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,6002025-11-11 MEDIUM 6.7 CVE-2025-24918 Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware U… Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.8 CVE-2025-5718 The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be exploited if the Axis device… Axis Os 12.6.30+ Fix from $1,6002025-11-11 HIGH 7.2 CVE-2025-11578 A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to gain root SSH acces… Enterprise Server 3.14.20 / 3.15.15+ Fix from $1,9502025-11-10 MEDIUM 5.0 CVE-2025-64437 KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler does not verify whether the laun… Kubevirt 1.5.3+ Fix from $1,6002025-11-07 MEDIUM 5.6 CVE-2025-12418 Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a loca… Mitigation only Fix from $1,6002025-11-07 MEDIUM 5.5 CVE-2025-43446 This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An… macOS 14.8.2 / 15.7.2+ Fix from $1,6002025-11-04