Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,605 CVEs tagged with CWE-5946 Critical, 709 High, 668 Medium, 180 Low, 2 Unrated.

CVE-2025-41666

Published Jul 8, 2025

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchd…

CVSS 8.8 · High

CVE-2025-53109

Published Jul 2, 2025

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow ac…

CVSS 7.3 · High

CVE-2025-3771

Published Jun 26, 2025

A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, wh…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52936

Published Jun 23, 2025

Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.

CVSS 9.3 · Critical

CVE-2025-49157

Published Jun 17, 2025

A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49156

Published Jun 17, 2025

A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0913

Published Jun 11, 2025

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EX…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-5474

Published Jun 6, 2025

2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of 2…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-36564

Published Jun 3, 2025

Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local malicious user could potentially exploit this vulnerability, l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-54189

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is taken,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52561

Published Jun 3, 2025

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is delete…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36486

Published Jun 3, 2025

A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Desktop for Mac version 20.1.1 (55740). When an archived virtual…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11857

Published Jun 2, 2025

Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can create a symbolic link with the same name as a specific file, ca…

CVSS 8.5 · High

CVE-2025-31198

Published May 29, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A path handling issue was addr…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47181

Published May 22, 2025

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-2102

Published May 21, 2025

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: befo…

CVSS 5.7 · Medium

CVE-2025-3908

Published May 19, 2025

The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4211

Published May 16, 2025

Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and…

CVSS 7.3 · High

CVE-2025-20003

Published May 13, 2025

Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalati…

CVSS 7.3 · High

CVE-2025-29975

Published May 13, 2025

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 1,605 CVEsPage 13 of 65