CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,518 vulnerabilities with CWE-59
CVE-2026-2627
HIGH
Softland FBackup <9.9 - Path Traversal
CVSS 7.8
CVE-2026-26225
HIGH
Intego Personal Backup - Privilege Escalation
CVE-2026-20610
HIGH
macOS Tahoe <26.3 - Privilege Escalation
CVSS 7.8
CVE-2026-21517
MEDIUM
Windows App for Mac - Privilege Escalation
CVSS 4.7
CVE-2026-21419
MEDIUM
Dell Display and Peripheral Manager <2.2 - Privilege Escalation
CVSS 6.6
CVE-2026-24884
HIGH
compressing < 2.0.1 and < 1.10.4 - Arbitrary File Write via Symbolic Link Extraction
CVSS 8.4
CVE-2026-23563
MEDIUM
TeamViewer DEX - 1E Client <26.1 - Privilege Escalation
CVSS 5.7
CVE-2026-24842
HIGH
isaacs/tar < 7.5.7 - Path Traversal via Hardlink Entry Mismatch
CVSS 8.2
CVE-2026-24056
MEDIUM
pnpm < 10.28.2 - Unauthenticated Arbitrary File Read via Symlink in Local/Git Dependencies
CVSS 6.5
CVE-2026-23893
MEDIUM
openCryptoki >=2.3.2 - Privilege Escalation
CVSS 6.8
CVE-2026-24047
MEDIUM
@backstage/cli-common < 0.1.17 - Path Traversal via Symlink Chain Bypass
CVSS 6.3
CVE-2026-24046
HIGH
Backstage Scaffolder - Symlink-Based Path Traversal and Arbitrary File Read/Write via Template Actions
CVSS 7.1
CVE-2026-20941
HIGH
Host Process for Windows Tasks - Privilege Escalation
CVSS 7.8
CVE-2026-22702
MEDIUM
virtualenv < 20.36.1 - Symlink Race Condition via Directory Creation
CVSS 4.5
CVE-2026-22701
MEDIUM
filelock < 3.20.3 - TOCTOU Race Condition in SoftFileLock _acquire Method
CVSS 5.3
CVE-2025-46293
MEDIUM
Apple macOS < 15.4 - Improper Link Resolution Before File Access ('Link Following')
CVSS 5.5
CVE-2025-71212
HIGH
Trend Micro, Inc. TrendAI Apex One - Improper Link Resolution Before File Access ('Link Following')
CVSS 7.8
CVE-2025-27850
HIGH
Garmin WDU v1 1.4.6 & v2 5.0 - Path Traversal
CVSS 7.5
CVE-2025-43257
HIGH
macOS < 15.6 - Sandbox Escape via Symlink Handling
CVSS 8.7
CVE-2025-66680
HIGH
WiseCleaner Wise Force Deleter <=7.3.2 - Arbitrary File Deletion
CVSS 7.1
CVE-2025-48582
HIGH
Android - Unauthenticated Media Deletion via Intent Redirect
CVSS 8.4
CVE-2025-63946
HIGH
Tencent PC Manager <17.10.28554.205 - Privilege Escalation
CVSS 7.4
CVE-2025-63945
HIGH
Tencent iOA thru 210.9.28693.621001 - Privilege Escalation
CVSS 7.4
CVE-2025-66277
CRITICAL
QNAP QTS and QuTS hero - Unauthenticated Path Traversal via Symbolic Link Following
CVSS 9.8
CVE-2025-62676
HIGH
FortiClientWindows 7.0-7.4.4 - Arbitrary File Write via Crafted Named Pipe Messages
CVSS 7.1
Details
Vulnerabilities
1,518
Exploit Likelihood
Medium