CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,612 vulnerabilities with CWE-59
CVE-2026-67433
MEDIUM
Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration
CVE-2026-13268
HIGH
G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-13723
MEDIUM
Develar's electron-builder allows arbitrary file overwrite
CVSS 6.5
CVE-2026-43765
MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unauthorized File System Modification via Symlink Handling
CVSS 5.5
CVE-2026-17459
MEDIUM
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
CVSS 4.3
CVE-2026-12503
CRITICAL
Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter
CVE-2026-65069
MEDIUM
Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 4.0
CVE-2026-65068
LOW
Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-65067
LOW
Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-65066
LOW
Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-65065
MEDIUM
Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 5.5
CVE-2026-65064
LOW
Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-65063
LOW
Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-65062
LOW
Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-65061
LOW
Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-64617
LOW
Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-64616
LOW
Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.3
CVE-2026-64615
LOW
Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.3
CVE-2026-64614
LOW
Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW
CVSS 3.8
CVE-2026-64613
MEDIUM
Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW
CVSS 6.2
CVE-2026-47121
MEDIUM
Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta
CVSS 6.1
CVE-2026-15788
MEDIUM
WCOW cache mount source selector resolves NTFS junctions outside of cache root
CVE-2026-8170
HIGH
ExtremeXOS Privilege Escalation via Symlink Following in File Utilities
CVE-2026-58414
MEDIUM
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
CVSS 5.5
CVE-2026-16130
MEDIUM
nearai ironclaw write_file path_utils.rs validate_path link following
CVSS 4.4
Details
Vulnerabilities
1,612
Exploit Likelihood
Medium