Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,605 CVEs tagged with CWE-5946 Critical, 709 High, 668 Medium, 180 Low, 2 Unrated.

CVE-2025-22247

Published May 12, 2025

VMware Tools contains an insecure file handling vulnerability. A malicious actor with non-administrative privileges on a guest VM may tamper the local files to trigger insecure fi…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-9524

Published May 9, 2025

Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime Version 1.1.96.2 on Windows 10 x64 allows local attackers to…

CVSS 7.8 · High

CVE-2024-13962

Published May 9, 2025

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attacker…

CVSS 7.8 · High

CVE-2024-13961

Published May 9, 2025

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 on Windows 10 Pro x64 allows local attackers to escalate pri…

CVSS 7.8 · High

CVE-2024-13960

Published May 9, 2025

Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and…

CVSS 7.8 · High

CVE-2024-13959

Published May 9, 2025

Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows local attackers to escalate privileges and execute arbitra…

CVSS 7.8 · High

CVE-2024-13944

Published May 9, 2025

Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to…

CVSS 7.8 · High

CVE-2024-13759

Published May 9, 2025

Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attackers to gain system-level privileges via arbitrary file dele…

CVSS 7.8 · High

CVE-2025-3224

Published Apr 28, 2025

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1697

Published Apr 18, 2025

A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32817

Published Apr 16, 2025

A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this results in unauthorized file overwrite, potentially leading…

CVSS 6.1 · Medium

CVE-2025-29983

Published Apr 15, 2025

Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local acces…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23010

Published Apr 10, 2025

An Improper Link Resolution Before File Access ('Link Following') vulnerability in SonicWall NetExtender Windows (32 and 64 bit) client which allows an attacker to manipulate file…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-30457

Published Mar 31, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24278

Published Mar 31, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access p…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24242

Published Mar 31, 2025

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30371

Published Mar 28, 2025

Metabase is a business intelligence and embedded analytics tool. Versions prior to v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8 are vulnerable to circumvention of local link acces…

CVSS 2.1 · Low

CVE-2024-12905

Published Mar 27, 2025

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs whe…

CVSS 7.5 · High

CVE-2025-29795

Published Mar 23, 2025

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12390

Published Mar 20, 2025

A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without prope…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12216

Published Mar 20, 2025

A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and e…

CVSS 7.1 · High
Showing 326-350 of 1,605 CVEsPage 14 of 65