Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,606 CVEs tagged with CWE-5946 Critical, 709 High, 667 Medium, 170 Low, 14 Unrated.

CVE-2025-58373

Published Sep 5, 2025

Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where .rooignore protections could be bypassed u…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43726

Published Sep 2, 2025

Dell Alienware Command Center 5.x (AWCC), versions prior to 5.10.2.0, contains an Improper Link Resolution Before File Access ('Link Following')" vulnerability. A low privileged a…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54554

Published Aug 29, 2025

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-57749

Published Aug 20, 2025

n8n is a workflow automation platform. Before 1.106.0, a symlink traversal vulnerability was discovered in the Read/Write File node in n8n. While the node attempts to restrict acc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8612

Published Aug 20, 2025

AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-5296

Published Aug 18, 2025

CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary data to be written to protected locations, potentially lead…

CVSS 7.0 · High

CVE-2025-8959

Published Aug 15, 2025

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-43490

Published Aug 15, 2025

A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support software, which might allow escalation of privilege. HP is…

CVSS 8.4 · High

CVE-2025-55188

Published Aug 8, 2025

7-Zip before 25.01 does not always properly handle symbolic links during extraction.

CVSS 3.6 · Low
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-54798

Published Aug 7, 2025

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / directory write via symbolic link dir pa…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43252

Published Jul 30, 2025

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15.6. A website may be able to access sensitive user data when resol…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43220

Published Jul 30, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-23267

Published Jul 17, 2025

NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted contain…

CVSS 8.5 · High

CVE-2025-7012

Published Jul 13, 2025

An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to root by exploiting improper symbolic link handling.

CVSS 8.6 · High

CVE-2025-52837

Published Jul 10, 2025

Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportun…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48384

Published Jul 8, 2025

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading…

CVSS 8.0 · High
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-49738

Published Jul 8, 2025

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21195

Published Jul 8, 2025

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-41668

Published Jul 8, 2025

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on t…

CVSS 8.8 · High
Showing 276-300 of 1,606 CVEsPage 12 of 65