CWE-59 · 1,604 records
Improper Link Resolution Before File Access ('Link Following')
CVEs in this class
1,606 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
77This week | CVE-2024-57728Weaponized | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading asimple-help · simplehelp · CWE-59 | High7.2 | KEV | 64.7% | Jan 15, 2025 |
74This week | CVE-2023-36874Weaponized | Windows Error Reporting Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-59 | High7.8 | KEV | 42.6% | Jul 11, 2023 |
74This week | CVE-2020-0787Weaponized | An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic lmicrosoft · windows 10 1507 · CWE-59 | High7.8 | KEV | 42.5% | Mar 12, 2020 |
73This week | CVE-2019-0841Weaponized | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elmicrosoft · windows 10 1703 · CWE-59 | High7.8 | KEV | 41.4% | Apr 9, 2019 |
64This week | CVE-2019-1253Weaponized | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerabmicrosoft · windows 10 1703 · CWE-59 | High7.8 | KEV | 11.6% | Sep 11, 2019 |
64This week | CVE-2015-1130Weaponized | The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privilegapple · mac os x · CWE-59 | High7.8 | KEV | 9.9% | Apr 10, 2015 |
63This week | CVE-2020-0683Weaponized | An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elemicrosoft · windows 10 1507 · CWE-59 | High7.8 | KEV | 7.6% | Feb 11, 2020 |
63This week | CVE-2019-1064Weaponized | Windows Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-59 | High7.8 | KEV | 6.9% | Jun 12, 2019 |
63This week | CVE-2019-1069Weaponized | Task Scheduler Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-59 | High7.8 | KEV | 6.1% | Jun 12, 2019 |
63This week | CVE-2025-48384Weaponized | Git allows arbitrary code execution through broken config quotinggit-scm · git · CWE-59 | High8.0 | KEV | 4.2% | Jul 8, 2025 |
62This week | CVE-2015-5287Weaponized | The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privredhat · automatic bug reporting tool · CWE-59 | High7.8 | KEV | 5.0% | Dec 7, 2015 |
62This week | CVE-2025-60710Weaponized | Host Process for Windows Tasks Elevation of Privilege Vulnerabilitymicrosoft · windows 11 24h2 · CWE-59 | High7.8 | KEV | 4.6% | Nov 11, 2025 |
62This week | CVE-2019-1385Weaponized | An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resultimicrosoft · windows 10 1709 · CWE-59 | High7.8 | KEV | 3.6% | Nov 12, 2019 |
62This week | CVE-2019-1315Weaponized | An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reportmicrosoft · windows 10 1607 · CWE-59 | High7.8 | KEV | 3.5% | Oct 10, 2019 |
62This week | CVE-2020-0638Weaponized | An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an atmicrosoft · windows 10 1709 · CWE-59 | High7.8 | KEV | 2.4% | Jan 14, 2020 |
62This week | CVE-2019-1129Weaponized | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elmicrosoft · windows 10 1703 · CWE-59 | High7.8 | KEV | 1.8% | Jul 15, 2019 |
62This week | CVE-2019-1130Weaponized | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elmicrosoft · windows 10 1507 · CWE-59 | High7.8 | KEV | 1.7% | Jul 15, 2019 |
61This week | CVE-2026-41091Weaponized | Microsoft Defender Elevation of Privilege Vulnerabilitymicrosoft · malware protection engine · CWE-59 | High7.8 | KEV | 0.4% | May 20, 2026 |
61This week | CVE-2026-81963Weaponized | Windows Update Stack Elevation of Privilege Vulnerabilitymicrosoft · windows 11 23h2 · CWE-59 | High7.8 | KEV | 0.4% | Sep 8, 2026 |
59Plan | CVE-2022-21919Weaponized | Windows User Profile Service Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-59 | High7.0 | KEV | 2.4% | Jan 11, 2022 |
59Plan | CVE-2025-21391Weaponized | Windows Storage Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-59 | High7.1 | KEV | 2.3% | Feb 11, 2025 |
58Plan | CVE-2021-41379Weaponized | Windows Installer Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-59 | Medium5.5 | KEV | 19.5% | Nov 9, 2021 |
57Plan | CVE-2021-21300Weaponized | malicious repositories can execute remote code while cloninggit-scm · git · CWE-59 | High7.5 | — | 88.5% | Mar 9, 2021 |
50Plan | CVE-2021-32610No exploit | In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.php · archive tar · CWE-59 | High7.1 | — | 73.4% | Jul 30, 2021 |
42Plan | CVE-2017-1002101Proof of concept | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with kubernetes · kubernetes · CWE-59 | Critical9.6 | — | 12.9% | Mar 13, 2018 |
- CVE-2024-5772877This week
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a
HighCVSS 7.2KEVWeaponizedEPSS 65%simple-help · simplehelpJan 15, 2025
- CVE-2023-3687474This week
Windows Error Reporting Service Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 43%microsoft · windows 10 1507Jul 11, 2023
- CVE-2020-078774This week
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic l
HighCVSS 7.8KEVWeaponizedEPSS 43%microsoft · windows 10 1507Mar 12, 2020
- CVE-2019-084173This week
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El
HighCVSS 7.8KEVWeaponizedEPSS 41%microsoft · windows 10 1703Apr 9, 2019
- CVE-2019-125364This week
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerab
HighCVSS 7.8KEVWeaponizedEPSS 12%microsoft · windows 10 1703Sep 11, 2019
- CVE-2015-113064This week
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileg
HighCVSS 7.8KEVWeaponizedEPSS 10%apple · mac os xApr 10, 2015
- CVE-2020-068363This week
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Ele
HighCVSS 7.8KEVWeaponizedEPSS 8%microsoft · windows 10 1507Feb 11, 2020
- CVE-2019-106463This week
Windows Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 7%microsoft · windows 10 1607Jun 12, 2019
- CVE-2019-106963This week
Task Scheduler Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 6%microsoft · windows 10 1507Jun 12, 2019
- CVE-2025-4838463This week
Git allows arbitrary code execution through broken config quoting
HighCVSS 8.0KEVWeaponizedEPSS 4%git-scm · gitJul 8, 2025
- CVE-2015-528762This week
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain priv
HighCVSS 7.8KEVWeaponizedEPSS 5%redhat · automatic bug reporting toolDec 7, 2015
- CVE-2025-6071062This week
Host Process for Windows Tasks Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 5%microsoft · windows 11 24h2Nov 11, 2025
- CVE-2019-138562This week
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulti
HighCVSS 7.8KEVWeaponizedEPSS 4%microsoft · windows 10 1709Nov 12, 2019
- CVE-2019-131562This week
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Report
HighCVSS 7.8KEVWeaponizedEPSS 3%microsoft · windows 10 1607Oct 10, 2019
- CVE-2020-063862This week
An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an at
HighCVSS 7.8KEVWeaponizedEPSS 2%microsoft · windows 10 1709Jan 14, 2020
- CVE-2019-112962This week
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El
HighCVSS 7.8KEVWeaponizedEPSS 2%microsoft · windows 10 1703Jul 15, 2019
- CVE-2019-113062This week
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El
HighCVSS 7.8KEVWeaponizedEPSS 2%microsoft · windows 10 1507Jul 15, 2019
- CVE-2026-4109161This week
Microsoft Defender Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 0%microsoft · malware protection engineMay 20, 2026
- CVE-2026-8196361This week
Windows Update Stack Elevation of Privilege Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 0%microsoft · windows 11 23h2Sep 8, 2026
- CVE-2022-2191959Plan
Windows User Profile Service Elevation of Privilege Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 2%microsoft · windows 10 1507Jan 11, 2022
- CVE-2025-2139159Plan
Windows Storage Elevation of Privilege Vulnerability
HighCVSS 7.1KEVWeaponizedEPSS 2%microsoft · windows 10 1507Feb 11, 2025
- CVE-2021-4137958Plan
Windows Installer Elevation of Privilege Vulnerability
MediumCVSS 5.5KEVWeaponizedEPSS 19%microsoft · windows 10 1507Nov 9, 2021
- CVE-2021-2130057Plan
malicious repositories can execute remote code while cloning
HighCVSS 7.5WeaponizedEPSS 89%git-scm · gitMar 9, 2021
- CVE-2021-3261050Plan
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
HighCVSS 7.1No exploitEPSS 73%php · archive tarJul 30, 2021
- CVE-2017-100210142Plan
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with
CriticalCVSS 9.6Proof of conceptEPSS 13%kubernetes · kubernetesMar 13, 2018