Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,606 CVEs tagged with CWE-5946 Critical, 709 High, 667 Medium, 170 Low, 14 Unrated.

CVE-2025-12418

Published Nov 7, 2025

Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an un…

CVSS 5.6 · Medium

CVE-2025-43446

Published Nov 4, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to modify pro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43395

Published Nov 4, 2025

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access prote…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43394

Published Nov 4, 2025

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to access prote…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43288

Published Nov 4, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypass Privacy preferences.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9871

Published Oct 29, 2025

Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9870

Published Oct 29, 2025

Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9869

Published Oct 29, 2025

Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-12341

Published Oct 28, 2025

A vulnerability was detected in ermig1979 AntiDupl up to 2.3.12. Impacted is an unknown function of the file AntiDupl.NET.WinForms.exe of the component Delete Duplicate Image Hand…

CVSS 7.1 · High

CVE-2025-26625

Published Oct 17, 2025

Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository's working tree with the contents of Git LFS object…

CVSS 8.6 · High

CVE-2025-59281

Published Oct 14, 2025

Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62363

Published Oct 13, 2025

yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the application allows users to configure the path to the yt-dlp executa…

CVSS 7.8 · High

CVE-2025-62364

Published Oct 13, 2025

text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character pic…

CVSS 6.2 · Medium

CVE-2025-9968

Published Oct 13, 2025

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially lea…

CVSS 8.5 · High

CVE-2025-11190

Published Oct 10, 2025

The Kiwire Captive Portal contains an open redirection issue via the login-url parameter, allowing an attacker to redirect users to an attacker controlled website.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11489

Published Oct 8, 2025

A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed of the file src/tools/filesystem…

CVSS 1.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-11462

Published Oct 7, 2025

Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1.3.2- 5.2.0 allows a local user to execute code with elevated privileges. Insufficient valida…

CVSS 9.3 · Critical

CVE-2025-41421

Published Oct 1, 2025

Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local…

CVSS 4.7 · Medium

CVE-2025-55317

Published Sep 9, 2025

Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,606 CVEsPage 11 of 65