Vulnerability index

Browse CVEs

188 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Link Following (Symlink)CWE-59 × clear
MEDIUM 6.7 CVE-2026-65680 Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. Onedrive No fix yet Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-72971 Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized att… Windows 11 26h1 10.0.28000.2704+ Fix from $4,0002026-08-11 MEDIUM 5.5 CVE-2026-70348 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-62832 Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges lo… Windows 10 21h2 10.0.19044.7663 / 10.0.19045.7663+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62812 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62803 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62807 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62776 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-62761 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-61358 Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker t… Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 MEDIUM 5.5 CVE-2026-50526 Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. .net 8.0.29 / 9.0.18+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-50469 Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges l… Windows 10 1809 10.0.17763.9020 / 10.0.19044.7548+ Fix from $1,9502026-07-14 HIGH 8.8 CVE-2026-50438 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.22.1.0+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-58636 Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-50364 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. Windows 10 21h2 10.0.19044.7548 / 10.0.19045.7548+ Fix from $1,9502026-07-14 HIGH 7.8 CVE-2026-49791 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to e… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-49180 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,6002026-07-14 HIGH 7.8 CVE-2026-49176 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 HIGH 7.4 CVE-2026-57991 Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose informa… Edge Chromium 150.0.4078.48+ Fix from $1,9502026-07-03 HIGH 7.0 CVE-2026-50656EPSS 11% Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP… Malware Protection Engine No fix yet Fix from $1,9502026-06-16 HIGH 7.8 CVE-2026-50511 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. Pc Manager 3.21.6.0+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-45586 Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 MEDIUM 5.5 CVE-2026-45491 Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. .net 8.0.28 / 9.0.17+ Fix from $1,6002026-06-09 HIGH 7.8 CVE-2026-42989 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9234 / 10.0.17763.8880+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-42834 Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. Windows Admin Center 0.72.0.0+ Fix from $1,9502026-05-20 HIGH 7.8 CVE-2026-41091 KEVEPSS 10% Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. Malware Protection Engine 1.1.26040.8+ Fix from $1,9502026-05-20 MEDIUM 5.0 CVE-2026-41610 Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass … Visual Studio Code 1.119.1+ Fix from $1,6002026-05-12 MEDIUM 5.5 CVE-2026-32212 Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose inform… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 HIGH 7.8 CVE-2026-25187 Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8957 / 10.0.17763.8511+ Fix from $1,9502026-03-10 HIGH 7.0 CVE-2026-21517 Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. Windows App 11.3.2+ Fix from $1,9502026-02-10