CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,613 vulnerabilities with CWE-59
CVE-2025-41421
MEDIUM
TeamViewer <15.70 - Privilege Escalation
CVSS 4.7
CVE-2025-34194
HIGH
Vasion Print Virtual Appliance Host < 25.1.102 & Application < 25.1.1413 - Local Privilege Escalation
CVSS 7.8
CVE-2025-34191
HIGH
Vasion Print Virtual Appliance Host < 22.0.843 & Application < 20.0.1923 - Arbitrary File Write
CVSS 8.4
CVE-2025-55317
HIGH
Microsoft AutoUpdate - Privilege Escalation
CVSS 7.8
CVE-2025-55245
HIGH
Xbox Gaming Services < 30.104.13001.0 - Authenticated Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-58373
MEDIUM
Roo Code <3.25.23 - Privilege Escalation
CVSS 5.5
CVE-2025-43726
MEDIUM
Dell Alienware Command Center < 5.10.2.0 - Privilege Escalation via Improper Link Resolution
CVSS 6.7
CVE-2025-57749
MEDIUM
n8n < 1.106.0 - Symlink Traversal in Read/Write File Node
CVSS 6.5
CVE-2025-8612
HIGH
AOMEI Backupper Workstation - Local Privilege Escalation via Junction Link Following
CVSS 7.3
CVE-2025-5296
HIGH
Link Following - Privilege Escalation
CVSS 7.3
CVE-2025-8959
HIGH
HashiCorp go-getter < 1.7.9 - Unauthorized Read Access via Symlink Attack
CVSS 7.5
CVE-2025-43490
HIGH
HP Hotkey Support - Privilege Escalation
CVE-2025-55188
LOW
7-Zip < 25.01 - Improper Link Resolution During Extraction
CVSS 3.6
CVE-2025-54798
LOW
raszi/tmp < 0.2.4 - Arbitrary File Write via Symbolic Link
CVSS 2.5
CVE-2025-36611
HIGH
Dell Encryption and Security Management Server < 11.11.0 - Privilege Escalation via Improper Link Resolution
CVSS 7.3
CVE-2025-43252
MEDIUM
macOS Sequoia <15.6 - Info Disclosure
CVSS 6.5
CVE-2025-43220
CRITICAL
iPadOS < 17.7.9 and macOS < 13.7.7, < 14.7.7, < 15.6 - Unprotected User Data Exposure via Symlink Validation Bypass
CVSS 9.8
CVE-2025-23267
HIGH
NVIDIA Container Toolkit < 1.17.8 - Data Tampering and Denial of Service via update-ldcache Hook
CVSS 8.5
CVE-2025-7012
HIGH
Cato Networks' CatoClient for Linux <5.5 - Privilege Escalation
CVE-2025-52837
HIGH
Trend Micro Password Manager < 5.8.0.1330 - Privilege Escalation via Symbolic Link Abuse
CVSS 7.8
CVE-2025-48384
HIGH
KEV
Git < 2.43.7 - Unauthenticated Arbitrary Code Execution via Submodule Path Traversal
CVSS 8.0
CVE-2025-49739
HIGH
Visual Studio 2017, 2019, 2022 - Privilege Escalation via Improper Link Resolution
CVSS 8.8
CVE-2025-49738
HIGH
Microsoft PC Manager < 3.17.4.0 - Privilege Escalation via Improper Link Resolution
CVSS 7.8
CVE-2025-49680
HIGH
Windows Performance Recorder - Denial of Service via Improper Link Resolution
CVSS 7.3
CVE-2025-48820
HIGH
Windows AppX Deployment Service - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
1,613
Exploit Likelihood
Medium