Перейти к содержимому
Noroxi

CWE-61 · 136 записей

UNIX Symbolic Link (Symlink) Following

CVE этого класса

136 записей

  • CVE-2026-54420
    64На этой неделе

    LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP

    ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 1 %

    litespeedtech · litespeed cpanel plugin14 июн. 2026 г.

  • CVE-2024-54661
    39Наблюдать

    readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dest-unreach · socat4 дек. 2024 г.

  • CVE-2025-23394
    39Наблюдать

    daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    suse · opensuse tumbleweed26 мая 2025 г.

  • CVE-2026-55447
    38Наблюдать

    Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    langflow · langflow23 июн. 2026 г.

  • CVE-2025-68937
    38Наблюдать

    Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-

    КритическаяCVSS 9,5Proof of conceptEPSS 1 %

    forgejo · forgejo25 дек. 2025 г.

  • CVE-2026-34078
    37Наблюдать

    Flatpak has a complete sandbox escape leading to host file access and code execution in the host context

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    flatpak · flatpak7 апр. 2026 г.

  • CVE-2025-55345
    35Наблюдать

    Unsafe symlink following in restricted workspace-write sandbox leads to RCE

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    13 авг. 2025 г.

  • CVE-2024-22014
    35Наблюдать

    An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbol

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    360totalsecurity · 360 total security15 апр. 2024 г.

  • CVE-2026-27976
    35Наблюдать

    Zed Extension Sandbox Escape via Tar Symlink Following

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    zed · zed25 февр. 2026 г.

  • CVE-2024-52535
    35Наблюдать

    Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symboli

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    dell · supportassist for business pcs25 дек. 2024 г.

  • CVE-2024-45418
    35Наблюдать

    Zoom Apps for macOS - Symbolic Link Following

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    zoom · meeting software development kit25 февр. 2025 г.

  • CVE-2026-6475
    35Наблюдать

    PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    postgresql · postgresql14 мая 2026 г.

  • CVE-2026-56748
    34Наблюдать

    Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    cribl · cribl stream27 июл. 2026 г.

  • CVE-2026-41937
    34Наблюдать

    Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    givanz · vvveb14 мая 2026 г.

  • CVE-2025-57802
    34Наблюдать

    Airlink's Daemon Symlink Vulnerability

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    airlinklabs · daemon25 авг. 2025 г.

  • CVE-2026-12958
    34Наблюдать

    Arbitrary file write in Language Servers for AWS

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    amazon web services · language servers for aws23 июн. 2026 г.

  • CVE-2025-46810
    34Наблюдать

    A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    opensuse · tumbleweed2 сент. 2025 г.

  • CVE-2026-49248
    33Наблюдать

    OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    theonedev · onedev18 июн. 2026 г.

  • CVE-2025-52565
    33Наблюдать

    container escape due to /dev/console mount and related races

    ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %

    linuxfoundation · runc6 нояб. 2025 г.

  • CVE-2025-33225
    33Наблюдать

    NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names.

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    nvidia · nvidia resiliency extension16 дек. 2025 г.

  • CVE-2026-53802
    33Наблюдать

    rsync < 3.5.0 Arbitrary File Read via Symlink Following

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    samba · rsync13 авг. 2026 г.

  • CVE-2026-39860
    33Наблюдать

    Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    linux · linux kernel8 апр. 2026 г.

  • CVE-2024-47515
    32Наблюдать

    Pagure: generate_archive() follows symbolic links in temporary clones

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    24 дек. 2024 г.

  • CVE-2026-35525
    32Наблюдать

    LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    liquidjs · liquidjs8 апр. 2026 г.

  • CVE-2025-10854
    32Наблюдать

    Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indices

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    22 сент. 2025 г.

Все классы уязвимостей