VulnSea

CWE-59

CVEs classified under CWE-59, newest first.

218 CVEsRSS

CVE-2026-43998High· 8.5
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. B…

▾ Twilightvm2_project · vm2EPSS 0.85%via NVD
CVE-2026-39819Medium· 4.4
4mo ago

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

▾ Sunlittoolchain · toolchainEPSS 0.15%via OSV
CVE-2026-33694High· 7.8
5mo ago

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit th…

▾ Twilighttenable · nessusEPSS 0.20%via NVD
CVE-2026-4135Medium· 6.6
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

▾ Sunlitlenovo · software_fixEPSS 0.15%via NVD
CVE-2026-0827High· 7.1PoC
5mo ago

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authentica…

▾ Midnightlenovo · diagnosticsEPSS 0.21%via NVD
CVE-2026-32212Medium· 5.5
5mo ago

Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.37%via CVEORG
CVE-2026-34078Critical· 10.0
5mo ago

Flatpak is a Linux application sandboxing and distribution framework

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at arbitrary paths. Flatpak run mounts th…

▾ Midnightflatpak · flatpakEPSS 0.90%via NVD
CVE-2026-27456Medium· 4.7
5mo ago

util-linux is a random collection of Linux utilities

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up lo…

▾ Sunlitkernel · util-linuxEPSS 0.12%via NVD
CVE-2026-33001High· 8.8
6mo ago

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted on…

Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted on…

▾ Twilightjenkins · jenkinsEPSS 1.2%via NVD
CVE-2026-29786Medium· 6.3PoC
6mo ago

node-tar is a full-featured Tar for Node.js

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables f…

▾ Twilightisaacs · tarEPSS 0.39%via NVD
CVE-2026-24842High· 8.2
8mo ago

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attac…

▾ Twilightisaacs · tarEPSS 0.62%via NVD
CVE-2026-24046High· 7.1
8mo ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder…

▾ TwilightEPSS 0.53%via NVD
CVE-2025-43448Medium· 6.3
10mo ago

This issue was addressed with improved validation of symlinks

This issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS …

▾ Sunlitapple · ipadosEPSS 0.29%via NVD
CVE-2025-9968None
11mo ago

A link following vulnerability exists in the UnifyScanner component of Armoury Crate

A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggered by creating a specially crafted junction, potentially leading to local privilege escalation. For more information, …

▾ SunlitEPSS 0.20%via NVD
CVE-2024-54554Medium· 5.5
1y ago

This issue was addressed with improved handling of symlinks

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.18%via NVD
CVE-2025-48384High· 8.0CISA KEVPoC
1y ago

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…

▾ Abyssalgit-scm · gitEPSS 4.1%via NVD
CVE-2025-52936None
1y ago

Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.

Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh: before 2.2.2.

▾ SunlitEPSS 0.19%via NVD
CVE-2025-4211None
1y ago

Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files

Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-21391High· 7.1CISA KEV0day
1y ago

Windows Storage Elevation of Privilege Vulnerability

Windows Storage Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 2.3%via NVD
CVE-2024-9341Medium· 5.4
1y ago

A flaw was found in Go

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic …

▾ Sunlitcontainers · commonEPSS 1.0%via NVD
CVE-2024-35254High· 7.1
2y ago

Azure Monitor Agent Elevation of Privilege Vulnerability

Azure Monitor Agent Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · azure_monitor_agentEPSS 0.83%via NVD
CVE-2024-35253Medium· 4.4
2y ago

Microsoft Azure File Sync Elevation of Privilege Vulnerability

Microsoft Azure File Sync Elevation of Privilege Vulnerability

▾ Sunlitmicrosoft · azure_file_syncEPSS 0.74%via NVD
CVE-2024-30104High· 7.8
2y ago

Microsoft Office Remote Code Execution Vulnerability

Microsoft Office Remote Code Execution Vulnerability

▾ Twilightmicrosoft · 365_appsEPSS 1.5%via NVD
CVE-2024-30093High· 7.3
2y ago

Windows Storage Elevation of Privilege Vulnerability

Windows Storage Elevation of Privilege Vulnerability

▾ Twilightmicrosoft · windows_10_1507EPSS 1.1%via NVD
CVE-2024-30076Medium· 6.8
2y ago

Windows Container Manager Service Elevation of Privilege Vulnerability

Windows Container Manager Service Elevation of Privilege Vulnerability

▾ Sunlitmicrosoft · windows_10_1607EPSS 1.7%via NVD
CVE-2024-30065Medium· 5.5
2y ago

Windows Themes Denial of Service Vulnerability

Windows Themes Denial of Service Vulnerability

▾ Sunlitmicrosoft · windows_10_1507EPSS 0.84%via NVD
CVE-2024-1753High· 8.6PoC
2y ago

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…

▾ MidnightRed Hat · buildahEPSS 0.49%via NVD
CVE-2022-32450High· 7.1
4y ago

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

▾ Twilightanydesk · anydeskEPSS 0.54%via NVD
CVE-2022-30333High· 7.5CISA KEVPoC
4y ago

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

▾ Abyssalrarlab · unrarEPSS 99%via NVD
CVE-2021-41379Medium· 5.5CISA KEV0day
4y ago

Windows Installer Elevation of Privilege Vulnerability

Windows Installer Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · windows_10_1507EPSS 19%via NVD
CWE-59 vulnerabilities (CVEs) — page 7 · VulnSea