CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,613 vulnerabilities with CWE-59
CVE-2024-45418
MEDIUM
Zoom Meeting SDK < 6.1.5 - Authenticated Privilege Escalation via Symlink Following
CVSS 5.4
CVE-2024-57728
HIGH
KEV
SimpleHelp < 5.5.8 - Authenticated Path Traversal and Arbitrary File Write via Zip Slip
CVSS 7.2
CVE-2024-52050
HIGH
Trend Micro Apex One - Privilege Escalation
CVSS 7.8
CVE-2024-13043
HIGH
Panda Security Dome - Privilege Escalation
CVSS 7.8
CVE-2024-12753
HIGH
Foxit PDF Editor 11.0.0-11.2.11.54113 & Reader <2024.3.0.26795 - LPE via Installer Junction Abuse
CVSS 7.3
CVE-2024-12754
MEDIUM
AnyDesk - Information Disclosure via Junction Link Following in Background Image Handling
CVSS 5.5
CVE-2024-52535
HIGH
Dell SupportAssist for Home PCs < 4.6.2 and Business PCs < 4.5.1 - Authenticated Privilege Escalation via Symlink Attack
CVSS 7.1
CVE-2024-44211
MEDIUM
macOS < 15.1 - Unprotected User Data Exposure via Symlink Validation
CVSS 5.5
CVE-2024-47480
HIGH
Dell Inventory Collector Client <12.7.0 - Privilege Escalation
CVSS 7.8
CVE-2024-52542
MEDIUM
Dell AppSync 4.6.0.0-4.6.0.2 - Symbolic Link Following
CVSS 4.4
CVE-2024-56074
MEDIUM
gitingest <9996a06 - Path Traversal
CVSS 5.5
CVE-2024-12552
HIGH
Wacom Center - Local Privilege Escalation via Symbolic Link in WTabletServicePro
CVSS 7.8
CVE-2024-49107
HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2016-2019 - Elevation of Privilege via WmsRepair Service
CVSS 7.3
CVE-2024-49059
HIGH
Microsoft 365 Apps and Office - Elevation of Privilege via Race Condition
CVSS 7.0
CVE-2024-52537
MEDIUM
Dell Dock HD22Q, WD19, and WD22TB4 Firmware Update Utility - Privilege Escalation via Symlink Following
CVSS 6.3
CVE-2024-37143
CRITICAL
Dell PowerFlex and InsightIQ - Unauthenticated Arbitrary Code Execution via Improper Link Resolution
CVSS 10.0
CVE-2024-53691
HIGH
QNAP QTS and QuTS hero - Link Following via File System Traversal
CVSS 8.8
CVE-2024-50404
HIGH
Qsync Central 4.4.0-4.4.0.15 - Authenticated Path Traversal via Symbolic Link
CVSS 8.8
CVE-2024-22038
HIGH
obs-scm-bridge - Info Disclosure/DoS
CVSS 7.3
CVE-2024-7243
HIGH
Panda Security Dome - Local Privilege Escalation via Junction Link Following
CVSS 7.8
CVE-2024-7242
HIGH
Panda Security Dome - Local Privilege Escalation via Junction Abuse in PSANHost
CVSS 7.8
CVE-2024-7241
HIGH
Panda Security Dome - Local Privilege Escalation via Junction Creation in PSANHost Service
CVSS 7.8
CVE-2024-7240
HIGH
F-Secure Total - Local Privilege Escalation via Symbolic Link Abuse in WithSecure Plugin Hosting Service
CVSS 7.8
CVE-2024-7239
HIGH
VIPRE Advanced Security - Local Privilege Escalation via Symbolic Link Abuse in Anti Malware Service
CVSS 7.8
CVE-2024-7238
HIGH
VIPRE Advanced Security - Local Privilege Escalation via Symbolic Link Abuse in Anti Malware Service
CVSS 7.8
Details
Vulnerabilities
1,613
Exploit Likelihood
Medium