Skip to main content

CWE archive

CWE-59 CVEs

Programmatic archive

1,605 CVEs tagged with CWE-5946 Critical, 709 High, 668 Medium, 180 Low, 2 Unrated.

CVE-2024-10986

Published Mar 20, 2025

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-1683

Published Mar 12, 2025

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25185

Published Mar 3, 2025

GPT Academic provides interactive interfaces for large language models. In 3.91 and earlier, GPT Academic does not properly account for soft links. An attacker can create a malici…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-22480

Published Feb 13, 2025

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3432

Published Feb 12, 2025

A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24136

Published Jan 27, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious app may be able to…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24104

Published Jan 27, 2025

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24103

Published Jan 27, 2025

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access p…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0377

Published Jan 21, 2025

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-57728

Published Jan 15, 2025

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This…

CVSS 7.2 · High
evidence mentions
15
Buzz score
65.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-52050

Published Dec 31, 2024

A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacke…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13043

Published Dec 30, 2024

Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Se…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 1,605 CVEsPage 15 of 65