CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,463 vulnerabilities with CWE-59
CVE-2025-21347 MEDIUM
Microsoft Windows 10 1507 < 10.0.10240.20915 - Symlink Following
CVSS 6.0
CVE-2025-21322 HIGH
Microsoft PC Manager < 3.15.4.0 - Symlink Following
CVSS 7.8
CVE-2025-21188 MEDIUM
Microsoft Azure Network Watcher < 1.4.3563.1 - Symlink Following
CVSS 6.0
CVE-2025-0413 HIGH
Parallels Desktop - Privilege Escalation
CVSS 7.8
CVE-2025-0146 LOW
Zoom Workplace App for macOS <6.2.10 - DoS
CVSS 3.9
CVE-2025-24136 MEDIUM
Apple Macos < 13.7.3 - Symlink Following
CVSS 4.4
CVE-2025-24104 MEDIUM
Apple Ipados < 17.7.4 - Symlink Following
CVSS 5.5
CVE-2025-24103 MEDIUM
Apple Macos < 13.7.3 - Symlink Following
CVSS 5.5
CVE-2025-0377 HIGH
HashiCorp's go-slug - Path Traversal
CVSS 7.5
CVE-2025-21331 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20890 - Symlink Following
CVSS 7.3
CVE-2025-21274 MEDIUM
Microsoft Windows 10 1507 < 10.0.10240.20890 - Symlink Following
CVSS 5.5
CVE-2024-54554 MEDIUM
Apple Macos < 15.1 - Symlink Following
CVSS 5.5
CVE-2024-54189 HIGH
Parallels Desktop for Mac <20.1.1 - Privilege Escalation
CVSS 7.8
CVE-2024-52561 HIGH
Parallels Desktop - Symlink Following
CVSS 7.8
CVE-2024-36486 HIGH
Parallels Desktop for Mac <20.1.1 - Privilege Escalation
CVSS 7.8
CVE-2024-11857 HIGH
Realtek Bluetooth HCI Adaptor - Privilege Escalation
CVSS 7.8
CVE-2024-9524 HIGH
Avira Prime <1.1.96.2 - Local Privilege Escalation
CVSS 7.8
CVE-2024-13962 HIGH
Avast Cleanup Premium <24.2.16593.17810 - Privilege Escalation
CVSS 7.8
CVE-2024-13961 HIGH
Avast Cleanup Premium <24.2.16593.17810 - Privilege Escalation
CVSS 7.8
CVE-2024-13960 HIGH
AVG TuneUp <23.4-15592 - Privilege Escalation
CVSS 7.8
CVE-2024-13959 HIGH
AVG TuneUp <24.2.16593.9844 - Local Privilege Escalation
CVSS 7.8
CVE-2024-13944 HIGH
Norton Utilities Ultimate <24.2.16862.6344 - Privilege Escalation
CVSS 7.8
CVE-2024-13759 HIGH
Avira Prime <1.1.96.2 - Privilege Escalation
CVSS 7.8
CVE-2024-12905 HIGH
NPM Tar-fs < 1.16.4 - Path Traversal
CVSS 7.5
CVE-2024-12390 HIGH
Binary-husky Gpt Academic - Symlink Following
CVSS 8.8
Details
Vulnerabilities 1,463
Exploit Likelihood Medium