CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,518 vulnerabilities with CWE-59
CVE-2025-2102
MEDIUM
HYPR Passwordless <10.1 - Privilege Escalation
CVE-2025-3908
MEDIUM
OpenVPN 3 Linux <24 - Privilege Escalation
CVSS 6.2
CVE-2025-4211
HIGH
Qt < - Privilege Escalation
CVE-2025-20003
HIGH
Intel(R) Graphics Driver - Privilege Escalation
CVSS 8.2
CVE-2025-29975
HIGH
Microsoft PC Manager - Privilege Escalation
CVSS 7.8
CVE-2025-29837
MEDIUM
Windows Installer - Info Disclosure
CVSS 5.5
CVE-2025-1079
HIGH
Google Web Designer < 16.2.0.0128 - Remote Code Execution via Improper Symlink Resolution in Preview Feature
CVSS 7.8
CVE-2025-22247
MEDIUM
VMware Tools 11.x.x-12.x.x < 12.5.2 - Insecure File Handling via Local File Tampering
CVSS 6.1
CVE-2025-3224
HIGH
Docker Desktop for Windows <4.41.0 - Privilege Escalation
CVSS 7.8
CVE-2025-1697
HIGH
HP Touchpoint Analytics <4.2.2439 - Privilege Escalation
CVSS 7.8
CVE-2025-32817
MEDIUM
SonicWall Connect Tunnel - Path Traversal
CVSS 6.1
CVE-2025-29983
MEDIUM
Dell Trusted Device <7.0.3.0 - Privilege Escalation
CVSS 6.7
CVE-2025-23010
HIGH
SonicWall NetExtender - Path Traversal
CVSS 7.2
CVE-2025-27727
HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2008 - Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-21204
HIGH
Windows 10 1507-24H2 and Windows Server 2008 - Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-30457
CRITICAL
macOS <13.7.5-15.4-14.7.5 - Path Traversal
CVSS 9.8
CVE-2025-24278
MEDIUM
macOS < 13.7.5, < 14.7.5, < 15.4 - Unprotected User Data Exposure via Symlink Validation Bypass
CVSS 5.5
CVE-2025-24242
MEDIUM
macOS < 15.4 - Unprotected User Data Exposure via Symlink Handling
CVSS 4.4
CVE-2025-30371
LOW
Metabase <0.52.16.4, <1.52.16.4, <0.53.8, <1.53.8 - SSRF
CVE-2025-29795
HIGH
Microsoft Edge Update < 1.3.195.45 - Authenticated Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-1683
HIGH
1E Platform < 25.3 - Arbitrary File Deletion via Symbolic Link
CVSS 7.8
CVE-2025-25008
HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.1
CVE-2025-25185
HIGH
GPT Academic <3.91 - Info Disclosure
CVSS 7.5
CVE-2025-22480
HIGH
Dell SupportAssist OS Recovery < 5.5.13.1 - Arbitrary File Deletion and Privilege Escalation
CVSS 7.0
CVE-2025-21420
HIGH
Windows Disk Cleanup Tool - Elevation of Privilege via Improper Link Resolution
CVSS 7.8
Details
Vulnerabilities
1,518
Exploit Likelihood
Medium