Skip to content
Noroxi

CWE-59 · 1,604 records

Improper Link Resolution Before File Access ('Link Following')

CVEs in this class

1,606 records

  • CVE-2024-57728
    77This week

    SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a

    HighCVSS 7.2KEVWeaponizedEPSS 65%

    simple-help · simplehelpJan 15, 2025

  • CVE-2023-36874
    74This week

    Windows Error Reporting Service Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 43%

    microsoft · windows 10 1507Jul 11, 2023

  • CVE-2020-0787
    74This week

    An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic l

    HighCVSS 7.8KEVWeaponizedEPSS 43%

    microsoft · windows 10 1507Mar 12, 2020

  • CVE-2019-0841
    73This week

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El

    HighCVSS 7.8KEVWeaponizedEPSS 41%

    microsoft · windows 10 1703Apr 9, 2019

  • CVE-2019-1253
    64This week

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerab

    HighCVSS 7.8KEVWeaponizedEPSS 12%

    microsoft · windows 10 1703Sep 11, 2019

  • CVE-2015-1130
    64This week

    The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileg

    HighCVSS 7.8KEVWeaponizedEPSS 10%

    apple · mac os xApr 10, 2015

  • CVE-2020-0683
    63This week

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Ele

    HighCVSS 7.8KEVWeaponizedEPSS 8%

    microsoft · windows 10 1507Feb 11, 2020

  • CVE-2019-1064
    63This week

    Windows Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 7%

    microsoft · windows 10 1607Jun 12, 2019

  • CVE-2019-1069
    63This week

    Task Scheduler Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 6%

    microsoft · windows 10 1507Jun 12, 2019

  • CVE-2025-48384
    63This week

    Git allows arbitrary code execution through broken config quoting

    HighCVSS 8.0KEVWeaponizedEPSS 4%

    git-scm · gitJul 8, 2025

  • CVE-2015-5287
    62This week

    The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain priv

    HighCVSS 7.8KEVWeaponizedEPSS 5%

    redhat · automatic bug reporting toolDec 7, 2015

  • CVE-2025-60710
    62This week

    Host Process for Windows Tasks Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 5%

    microsoft · windows 11 24h2Nov 11, 2025

  • CVE-2019-1385
    62This week

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulti

    HighCVSS 7.8KEVWeaponizedEPSS 4%

    microsoft · windows 10 1709Nov 12, 2019

  • CVE-2019-1315
    62This week

    An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Report

    HighCVSS 7.8KEVWeaponizedEPSS 3%

    microsoft · windows 10 1607Oct 10, 2019

  • CVE-2020-0638
    62This week

    An elevation of privilege vulnerability exists in the way the Update Notification Manager handles files.To exploit this vulnerability, an at

    HighCVSS 7.8KEVWeaponizedEPSS 2%

    microsoft · windows 10 1709Jan 14, 2020

  • CVE-2019-1129
    62This week

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El

    HighCVSS 7.8KEVWeaponizedEPSS 2%

    microsoft · windows 10 1703Jul 15, 2019

  • CVE-2019-1130
    62This week

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows El

    HighCVSS 7.8KEVWeaponizedEPSS 2%

    microsoft · windows 10 1507Jul 15, 2019

  • CVE-2026-41091
    61This week

    Microsoft Defender Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 0%

    microsoft · malware protection engineMay 20, 2026

  • CVE-2026-81963
    61This week

    Windows Update Stack Elevation of Privilege Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 0%

    microsoft · windows 11 23h2Sep 8, 2026

  • Windows User Profile Service Elevation of Privilege Vulnerability

    HighCVSS 7.0KEVWeaponizedEPSS 2%

    microsoft · windows 10 1507Jan 11, 2022

  • Windows Storage Elevation of Privilege Vulnerability

    HighCVSS 7.1KEVWeaponizedEPSS 2%

    microsoft · windows 10 1507Feb 11, 2025

  • Windows Installer Elevation of Privilege Vulnerability

    MediumCVSS 5.5KEVWeaponizedEPSS 19%

    microsoft · windows 10 1507Nov 9, 2021

  • malicious repositories can execute remote code while cloning

    HighCVSS 7.5WeaponizedEPSS 89%

    git-scm · gitMar 9, 2021

  • In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

    HighCVSS 7.1No exploitEPSS 73%

    php · archive tarJul 30, 2021

  • In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with

    CriticalCVSS 9.6Proof of conceptEPSS 13%

    kubernetes · kubernetesMar 13, 2018

All vulnerability classes