Vulnerability index

Browse CVEs

188 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
Onedrive MEDIUM 6.7
CVE-2026-65680

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,000 2026-08-11
Windows 11 26h1 MEDIUM 5.5
CVE-2026-72971

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att…

Fix: 10.0.28000.2704+
Fix from $4,000 2026-08-11
Windows 11 24h2 MEDIUM 5.5
CVE-2026-70348

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

Fix: 10.0.26100.9106 / 10.0.26200.9106+
Fix from $4,000 2026-08-11
Windows 10 21h2 HIGH 7.8
CVE-2026-62832

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo…

Fix: 10.0.19044.7663 / 10.0.19045.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62812

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62803

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62807

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62776

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-62761

Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.

No fix yet
Fix from $4,900 2026-08-11
Windows 10 1809 HIGH 7.8
CVE-2026-61358

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker t…

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
.net MEDIUM 5.5
CVE-2026-50526

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

Fix: 8.0.29 / 9.0.18+
Fix from $1,600 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50469

Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges l…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Pc Manager HIGH 8.8
CVE-2026-50438

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.22.1.0+
Fix from $1,950 2026-07-14
Pc Manager HIGH 7.8
CVE-2026-58636

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-07-14
Windows 10 21h2 HIGH 7.3
CVE-2026-50364

Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49791

Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to e…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 MEDIUM 5.5
CVE-2026-49180

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,600 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-49176

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Edge Chromium HIGH 7.4
CVE-2026-57991

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose informa…

Fix: 150.0.4078.48+
Fix from $1,950 2026-07-03
Malware Protection Engine HIGH 7.0
CVE-2026-50656EPSS 11%

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP…

No fix yet
Fix from $1,950 2026-06-16
Pc Manager HIGH 7.8
CVE-2026-50511

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

Fix: 3.21.6.0+
Fix from $1,950 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-45586

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevat…

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
.net MEDIUM 5.5
CVE-2026-45491

Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.

Fix: 8.0.28 / 9.0.17+
Fix from $1,600 2026-06-09
Windows 10 1607 HIGH 7.8
CVE-2026-42989

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9234 / 10.0.17763.8880+
Fix from $1,950 2026-06-09
Windows Admin Center HIGH 7.8
CVE-2026-42834

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

Fix: 0.72.0.0+
Fix from $1,950 2026-05-20
Malware Protection Engine HIGH 7.8
CVE-2026-41091 KEVEPSS 10%

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Fix: 1.1.26040.8+
Fix from $1,950 2026-05-20
Visual Studio Code MEDIUM 5.0
CVE-2026-41610

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass …

Fix: 1.119.1+
Fix from $1,600 2026-05-12
Windows 10 1607 MEDIUM 5.5
CVE-2026-32212

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-25187

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8957 / 10.0.17763.8511+
Fix from $1,950 2026-03-10
Windows App HIGH 7.0
CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

Fix: 11.3.2+
Fix from $1,950 2026-02-10