CWE-61 · 136 записей
UNIX Symbolic Link (Symlink) Following
CVE этого класса
136 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2026-54420Готовый эксплойт | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTPlitespeedtech · litespeed cpanel plugin · CWE-61 | Высокая8,5 | KEV | 0,8 % | 14 июн. 2026 г. |
39Наблюдать | CVE-2024-54661Эксплойта нет | readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.dest-unreach · socat · CWE-61 | Критическая9,8 | — | 0,8 % | 4 дек. 2024 г. |
39Наблюдать | CVE-2025-23394Эксплойта нет | daily-backup.sh script in cyrus-imapd allows escalation from cyrus to rootsuse · opensuse tumbleweed · CWE-61 | Критическая9,8 | — | 0,6 % | 26 мая 2025 г. |
38Наблюдать | CVE-2026-55447Эксплойта нет | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitlangflow · langflow · CWE-61 | Критическая9,6 | — | 0,7 % | 23 июн. 2026 г. |
38Наблюдать | CVE-2025-68937Proof of concept | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-forgejo · forgejo · CWE-61 | Критическая9,5 | — | 0,5 % | 25 дек. 2025 г. |
37Наблюдать | CVE-2026-34078Эксплойта нет | Flatpak has a complete sandbox escape leading to host file access and code execution in the host contextflatpak · flatpak · CWE-61 | Критическая9,3 | — | 0,9 % | 7 апр. 2026 г. |
35Наблюдать | CVE-2025-55345Эксплойта нет | Unsafe symlink following in restricted workspace-write sandbox leads to RCECWE-61 | Высокая8,8 | — | 0,8 % | 13 авг. 2025 г. |
35Наблюдать | CVE-2024-22014Эксплойта нет | An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbol360totalsecurity · 360 total security · CWE-61 | Высокая8,8 | — | 0,8 % | 15 апр. 2024 г. |
35Наблюдать | CVE-2026-27976Эксплойта нет | Zed Extension Sandbox Escape via Tar Symlink Followingzed · zed · CWE-61 | Высокая8,8 | — | 0,7 % | 25 февр. 2026 г. |
35Наблюдать | CVE-2024-52535Эксплойта нет | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolidell · supportassist for business pcs · CWE-61 | Высокая8,8 | — | 0,6 % | 25 дек. 2024 г. |
35Наблюдать | CVE-2024-45418Эксплойта нет | Zoom Apps for macOS - Symbolic Link Followingzoom · meeting software development kit · CWE-61 | Высокая8,8 | — | 0,5 % | 25 февр. 2025 г. |
35Наблюдать | CVE-2026-6475Эксплойта нет | PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choicepostgresql · postgresql · CWE-61 | Высокая8,8 | — | 0,3 % | 14 мая 2026 г. |
34Наблюдать | CVE-2026-56748Эксплойта нет | Authenticated RCE via Symlink Following in Cribl Stream Pack Git Importcribl · cribl stream · CWE-61 | Высокая8,7 | — | 0,9 % | 27 июл. 2026 г. |
34Наблюдать | CVE-2026-41937Эксплойта нет | Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Uploadgivanz · vvveb · CWE-61 | Высокая8,6 | — | 0,6 % | 14 мая 2026 г. |
34Наблюдать | CVE-2025-57802Эксплойта нет | Airlink's Daemon Symlink Vulnerabilityairlinklabs · daemon · CWE-61 | Высокая8,7 | — | 0,4 % | 25 авг. 2025 г. |
34Наблюдать | CVE-2026-12958Эксплойта нет | Arbitrary file write in Language Servers for AWSamazon web services · language servers for aws · CWE-61 | Высокая8,5 | — | 0,2 % | 23 июн. 2026 г. |
34Наблюдать | CVE-2025-46810Эксплойта нет | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate opensuse · tumbleweed · CWE-61 | Высокая8,5 | — | 0,2 % | 2 сент. 2025 г. |
33Наблюдать | CVE-2026-49248Эксплойта нет | OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untartheonedev · onedev · CWE-61 | Высокая8,3 | — | 0,6 % | 18 июн. 2026 г. |
33Наблюдать | CVE-2025-52565Эксплойта нет | container escape due to /dev/console mount and related raceslinuxfoundation · runc · CWE-61 | Высокая8,4 | — | 0,6 % | 6 нояб. 2025 г. |
33Наблюдать | CVE-2025-33225Эксплойта нет | NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names.nvidia · nvidia resiliency extension · CWE-61 | Высокая8,4 | — | 0,3 % | 16 дек. 2025 г. |
33Наблюдать | CVE-2026-53802Эксплойта нет | rsync < 3.5.0 Arbitrary File Read via Symlink Followingsamba · rsync · CWE-61 | Высокая8,4 | — | 0,2 % | 13 авг. 2026 г. |
33Наблюдать | CVE-2026-39860Эксплойта нет | Nix sandbox escape: file write via symlink at FOD `.tmp` copy destinationlinux · linux kernel · CWE-61 | Высокая8,4 | — | 0,2 % | 8 апр. 2026 г. |
32Наблюдать | CVE-2024-47515Эксплойта нет | Pagure: generate_archive() follows symbolic links in temporary clonesCWE-61 | Высокая8,1 | — | 0,6 % | 24 дек. 2024 г. |
32Наблюдать | CVE-2026-35525Эксплойта нет | LiquidJS has a root restriction bypass for partial and layout loading through symlinked templatesliquidjs · liquidjs · CWE-61 | Высокая8,2 | — | 0,5 % | 8 апр. 2026 г. |
32Наблюдать | CVE-2025-10854Эксплойта нет | Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indicesCWE-61 | Высокая8,1 | — | 0,5 % | 22 сент. 2025 г. |
- CVE-2026-5442064На этой неделе
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP
ВысокаяCVSS 8,5KEVГотовый эксплойтEPSS 1 %litespeedtech · litespeed cpanel plugin14 июн. 2026 г.
- CVE-2024-5466139Наблюдать
readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dest-unreach · socat4 дек. 2024 г.
- CVE-2025-2339439Наблюдать
daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %suse · opensuse tumbleweed26 мая 2025 г.
- CVE-2026-5544738Наблюдать
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %langflow · langflow23 июн. 2026 г.
- CVE-2025-6893738Наблюдать
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-
КритическаяCVSS 9,5Proof of conceptEPSS 1 %forgejo · forgejo25 дек. 2025 г.
- CVE-2026-3407837Наблюдать
Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %flatpak · flatpak7 апр. 2026 г.
- CVE-2025-5534535Наблюдать
Unsafe symlink following in restricted workspace-write sandbox leads to RCE
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %13 авг. 2025 г.
- CVE-2024-2201435Наблюдать
An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbol
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %360totalsecurity · 360 total security15 апр. 2024 г.
- CVE-2026-2797635Наблюдать
Zed Extension Sandbox Escape via Tar Symlink Following
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zed · zed25 февр. 2026 г.
- CVE-2024-5253535Наблюдать
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symboli
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dell · supportassist for business pcs25 дек. 2024 г.
- CVE-2024-4541835Наблюдать
Zoom Apps for macOS - Symbolic Link Following
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %zoom · meeting software development kit25 февр. 2025 г.
- CVE-2026-647535Наблюдать
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %postgresql · postgresql14 мая 2026 г.
- CVE-2026-5674834Наблюдать
Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %cribl · cribl stream27 июл. 2026 г.
- CVE-2026-4193734Наблюдать
Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %givanz · vvveb14 мая 2026 г.
- CVE-2025-5780234Наблюдать
Airlink's Daemon Symlink Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %airlinklabs · daemon25 авг. 2025 г.
- CVE-2026-1295834Наблюдать
Arbitrary file write in Language Servers for AWS
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %amazon web services · language servers for aws23 июн. 2026 г.
- CVE-2025-4681034Наблюдать
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %opensuse · tumbleweed2 сент. 2025 г.
- CVE-2026-4924833Наблюдать
OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %theonedev · onedev18 июн. 2026 г.
- CVE-2025-5256533Наблюдать
container escape due to /dev/console mount and related races
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %linuxfoundation · runc6 нояб. 2025 г.
- CVE-2025-3322533Наблюдать
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names.
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %nvidia · nvidia resiliency extension16 дек. 2025 г.
- CVE-2026-5380233Наблюдать
rsync < 3.5.0 Arbitrary File Read via Symlink Following
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %samba · rsync13 авг. 2026 г.
- CVE-2026-3986033Наблюдать
Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %linux · linux kernel8 апр. 2026 г.
- CVE-2024-4751532Наблюдать
Pagure: generate_archive() follows symbolic links in temporary clones
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %24 дек. 2024 г.
- CVE-2026-3552532Наблюдать
LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %liquidjs · liquidjs8 апр. 2026 г.
- CVE-2025-1085432Наблюдать
Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indices
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %22 сент. 2025 г.