Skip to main content

CWE archive

CWE-1386 CVEs

Programmatic archive

15 CVEs tagged with CWE-13860 Critical, 3 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2026-41116

Published Jun 9, 2026

Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-58074

Published May 4, 2026

A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation pr…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-36340

Published May 13, 2025

A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosur…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7400

Published Sep 27, 2024

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without ha…

CVSS 8.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2023-32474

Published Feb 6, 2024

Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32454

Published Feb 6, 2024

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5834

Published Oct 27, 2023

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fix…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40623

Published Sep 12, 2023

SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with opera…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32470

Published Sep 8, 2023

Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1