CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,463 vulnerabilities with CWE-59
CVE-2025-60710 HIGH KEV
Host Process for Windows Tasks - Privilege Escalation
CVSS 7.8
CVE-2025-59510 MEDIUM
Microsoft Windows 10 1607 < 10.0.14393.8594 - Symlink Following
CVSS 5.5
CVE-2025-24918 MEDIUM
Intel Server Configuration Utility <16.0.12 - Privilege Escalation
CVSS 6.7
CVE-2025-5718 MEDIUM
Axis OS < 12.6.30 - Symlink Following
CVSS 6.8
CVE-2025-11578 HIGH
Github Enterprise Server < 3.14.20 - Symlink Following
CVSS 7.2
CVE-2025-64437 MEDIUM
Kubevirt < 1.5.3 - Symlink Following
CVSS 5.0
CVE-2025-12418 MEDIUM
Revenera InstallShield <2025 R1 - DoS
CVE-2025-43448 MEDIUM
Apple Products - Sandbox Escape
CVSS 6.3
CVE-2025-43446 MEDIUM
macOS - Info Disclosure
CVSS 5.5
CVE-2025-43395 LOW
macOS - Info Disclosure
CVSS 3.3
CVE-2025-43394 MEDIUM
macOS - Info Disclosure
CVSS 5.5
CVE-2025-43379 MEDIUM
Apple - Info Disclosure
CVSS 5.5
CVE-2025-43288 MEDIUM
macOS Sequoia <15.7 - Privilege Escalation
CVSS 5.5
CVE-2025-9871 HIGH
Razer Synapse < 3.10.730.71519 - Symlink Following
CVSS 7.8
CVE-2025-9870 HIGH
Razer Synapse < 3.10.730.71519 - Symlink Following
CVSS 7.8
CVE-2025-9869 HIGH
Razer Synapse < 3.10.730.71519 - Symlink Following
CVSS 7.8
CVE-2025-12341 HIGH
ermig1979 AntiDupl <2.3.12 - SSRF
CVSS 7.8
CVE-2025-26625 HIGH
Git-lfs < 3.7.1 - Symlink Following
CVE-2025-59281 HIGH
Microsoft Xbox Gaming Services < 31.105.17001.0 - Symlink Following
CVSS 7.8
CVE-2025-59241 HIGH
Microsoft Windows 11 24h2 < 10.0.26100.6899 - Symlink Following
CVSS 7.8
CVE-2025-55247 HIGH
.NET - Privilege Escalation
CVSS 7.3
CVE-2025-62363 HIGH
yt-grabber-tui <1.0-rc - Code Injection
CVSS 7.8
CVE-2025-62364 MEDIUM
text-generation-webui <3.13 - Local File Inclusion
CVSS 6.2
CVE-2025-9968 HIGH
Armoury Crate - Privilege Escalation
CVE-2025-11190 MEDIUM
Kiwire Captive Portal - Open Redirect
CVSS 5.4
Details
Vulnerabilities 1,463
Exploit Likelihood Medium