CWE-61

High likelihood

UNIX Symbolic Link (Symlink) Following

Parent: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

125 vulnerabilities with CWE-61
CVE-2025-5468 MEDIUM
Ivanti Connect Secure <22.7R2.8, Policy Secure <22.7R1.5, ZTA Gatew...
CVSS 5.5
CVE-2025-36564 HIGH
Dell Encryption < 11.10.2 - Symlink Following
CVSS 7.8
CVE-2025-23394 CRITICAL
openSUSE Tumbleweed cyrus-imapd <3.8.4.2.1 - Privilege Escalation
CVSS 9.8
CVE-2025-43853 MEDIUM
WAMR <2.2.0 - Path Traversal
CVSS 5.5
CVE-2025-1079 HIGH
Google Web Designer - RCE
CVSS 7.8
CVE-2025-30485 MEDIUM
FutureNet NXR/WXR/VXR - Info Disclosure
CVSS 6.2
CVE-2025-3048 MEDIUM
AWS SAM CLI <1.134.0 - Info Disclosure
CVSS 6.5
CVE-2025-3047 MEDIUM
SAM CLI <v1.133.0 - Privilege Escalation
CVSS 6.5
CVE-2025-29787 HIGH
Crates.io Zip < 2.3.0 - Path Traversal
CVE-2025-24832 MEDIUM
Acronis Backup - Privilege Escalation
CVSS 5.5
CVE-2025-22480 HIGH
Dell Supportassist OS Recovery < 5.5.13.1 - Symlink Following
CVSS 7.0
CVE-2025-24886 HIGH
pwn.college - LFI
CVSS 7.7
CVE-2024-45418 MEDIUM
Zoom <6.1.5 - Privilege Escalation
CVSS 5.4
CVE-2024-52535 HIGH
Dell Supportassist For Business Pcs < 4.5.1 - Symlink Following
CVSS 7.1
CVE-2024-47515 HIGH
Pagure - Info Disclosure
CVSS 8.1
CVE-2024-54148 CRITICAL
Gogs - Path Traversal
CVSS 9.8
CVE-2024-47480 HIGH
Dell Inventory Collector Client <12.7.0 - Privilege Escalation
CVSS 7.8
CVE-2024-52542 MEDIUM
Dell Appsync < 4.6.0.3 - Symlink Following
CVSS 4.4
CVE-2024-52537 MEDIUM
Dell Dock Hd22q Firmware Update Utility < 1.00.23 - Symlink Following
CVSS 6.3
CVE-2024-54661 CRITICAL
socat <1.8.0.2 - Info Disclosure
CVSS 9.8
CVE-2024-52522 MEDIUM
Rclone < 1.68.2 - Symlink Following
CVE-2024-34015 LOW
Acronis Backup <1.8.3.818-1.9.1.892 - Info Disclosure
CVSS 3.3
CVE-2024-34014 MEDIUM
Acronis Backup - Improper Symbolic Link Handling
CVSS 5.5
CVE-2024-0134 MEDIUM
NVIDIA Container Toolkit - Info Disclosure
CVSS 4.1
CVE-2024-47877 HIGH
Extract <4.0.0 - Path Traversal
CVSS 7.5
Details
Vulnerabilities 125
Exploit Likelihood High