CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,463 vulnerabilities with CWE-59
CVE-2025-15319 HIGH
Tanium Patch Endpoint Tools - Privilege Escalation
CVSS 7.8
CVE-2025-15318 MEDIUM
Tanium - Path Traversal
CVSS 5.5
CVE-2025-15328 MEDIUM
Enforce < 2.7.314 - Symlink Following
CVSS 5.0
CVE-2025-15324 MEDIUM
Tanium Engage < 1.3.37 - Symlink Following
CVSS 6.6
CVE-2025-69431 MEDIUM
Zspace Q2c Firmware < 1.1.0210050 - Symlink Following
CVSS 6.1
CVE-2025-69430 MEDIUM
Yottamaster Dm2 Firmware < 1.9.12 - Symlink Following
CVSS 6.1
CVE-2025-69429 MEDIUM
Orico Cd3510 Firmware < 1.9.12 - Symlink Following
CVSS 6.1
CVE-2025-15543 MEDIUM
VX800v 1.0 - Info Disclosure
CVSS 4.6
CVE-2025-15541 MEDIUM
VX800v v1.0 - Path Traversal
CVSS 6.3
CVE-2025-67124 MEDIUM
Svenstaro Miniserve < 0.32.0 - Symlink Following
CVSS 6.8
CVE-2025-13154 MEDIUM
Lenovo Vantage - Privilege Escalation
CVSS 5.5
CVE-2025-53594 MEDIUM
Qfinder Pro Mac <7.13.0 - Path Traversal
CVE-2025-12838 HIGH
MSP360 Free Backup - Privilege Escalation
CVSS 7.3
CVE-2025-68279 HIGH
Weblate < 5.15.1 - Information Disclosure
CVSS 7.7
CVE-2025-68146 MEDIUM
Pypi Filelock < 3.20.1 - Race Condition
CVSS 6.3
CVE-2025-14693 MEDIUM
Ugreen DH2100+ <5.3.0 - Symlink Following
CVSS 6.2
CVE-2025-43461 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-43381 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-7073 HIGH
Bitdefender Antivirus < 30.0.25.77 - Symlink Following
CVSS 7.8
CVE-2025-66626 HIGH
Argo Workflows <3.7.4 - Code Injection
CVSS 8.1
CVE-2025-46637 HIGH
Dell Encryption <11.12.1 - Privilege Escalation
CVSS 7.3
CVE-2025-46636 MEDIUM
Dell Encryption <11.12.1 - Info Disclosure
CVSS 6.6
CVE-2025-67487 HIGH
Static-web-server Static Web Server < 2.40.0 - Symlink Following
CVSS 8.6
CVE-2025-65843 HIGH
Aquarius Desktop 3.0.069 - Path Traversal
CVSS 7.7
CVE-2025-34352 HIGH
JumpCloud Remote Assist for Windows <0.317.0 - Privilege Escalation
Details
Vulnerabilities 1,463
Exploit Likelihood Medium