CWE-61 · 136 kayıt
UNIX Symbolic Link (Symlink) Following
Bu sınıftaki CVE’ler
136 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2026-54420Silahlaştırılmış | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTPlitespeedtech · litespeed cpanel plugin · CWE-61 | Yüksek8,5 | KEV | %0,8 | 14 Haz 2026 |
39İzleyin | CVE-2024-54661İstismar yok | readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.dest-unreach · socat · CWE-61 | Kritik9,8 | — | %0,8 | 4 Ara 2024 |
39İzleyin | CVE-2025-23394İstismar yok | daily-backup.sh script in cyrus-imapd allows escalation from cyrus to rootsuse · opensuse tumbleweed · CWE-61 | Kritik9,8 | — | %0,6 | 26 May 2025 |
38İzleyin | CVE-2026-55447İstismar yok | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploitlangflow · langflow · CWE-61 | Kritik9,6 | — | %0,7 | 23 Haz 2026 |
38İzleyin | CVE-2025-68937Kavram kanıtı | Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-forgejo · forgejo · CWE-61 | Kritik9,5 | — | %0,5 | 25 Ara 2025 |
37İzleyin | CVE-2026-34078İstismar yok | Flatpak has a complete sandbox escape leading to host file access and code execution in the host contextflatpak · flatpak · CWE-61 | Kritik9,3 | — | %0,9 | 7 Nis 2026 |
35İzleyin | CVE-2025-55345İstismar yok | Unsafe symlink following in restricted workspace-write sandbox leads to RCECWE-61 | Yüksek8,8 | — | %0,8 | 13 Ağu 2025 |
35İzleyin | CVE-2024-22014İstismar yok | An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbol360totalsecurity · 360 total security · CWE-61 | Yüksek8,8 | — | %0,8 | 15 Nis 2024 |
35İzleyin | CVE-2026-27976İstismar yok | Zed Extension Sandbox Escape via Tar Symlink Followingzed · zed · CWE-61 | Yüksek8,8 | — | %0,7 | 25 Şub 2026 |
35İzleyin | CVE-2024-52535İstismar yok | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolidell · supportassist for business pcs · CWE-61 | Yüksek8,8 | — | %0,6 | 25 Ara 2024 |
35İzleyin | CVE-2024-45418İstismar yok | Zoom Apps for macOS - Symbolic Link Followingzoom · meeting software development kit · CWE-61 | Yüksek8,8 | — | %0,5 | 25 Şub 2025 |
35İzleyin | CVE-2026-6475İstismar yok | PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choicepostgresql · postgresql · CWE-61 | Yüksek8,8 | — | %0,3 | 14 May 2026 |
34İzleyin | CVE-2026-56748İstismar yok | Authenticated RCE via Symlink Following in Cribl Stream Pack Git Importcribl · cribl stream · CWE-61 | Yüksek8,7 | — | %0,9 | 27 Tem 2026 |
34İzleyin | CVE-2026-41937İstismar yok | Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Uploadgivanz · vvveb · CWE-61 | Yüksek8,6 | — | %0,6 | 14 May 2026 |
34İzleyin | CVE-2025-57802İstismar yok | Airlink's Daemon Symlink Vulnerabilityairlinklabs · daemon · CWE-61 | Yüksek8,7 | — | %0,4 | 25 Ağu 2025 |
34İzleyin | CVE-2026-12958İstismar yok | Arbitrary file write in Language Servers for AWSamazon web services · language servers for aws · CWE-61 | Yüksek8,5 | — | %0,2 | 23 Haz 2026 |
34İzleyin | CVE-2025-46810İstismar yok | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate opensuse · tumbleweed · CWE-61 | Yüksek8,5 | — | %0,2 | 2 Eyl 2025 |
33İzleyin | CVE-2026-49248İstismar yok | OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untartheonedev · onedev · CWE-61 | Yüksek8,3 | — | %0,6 | 18 Haz 2026 |
33İzleyin | CVE-2025-52565İstismar yok | container escape due to /dev/console mount and related raceslinuxfoundation · runc · CWE-61 | Yüksek8,4 | — | %0,6 | 6 Kas 2025 |
33İzleyin | CVE-2025-33225İstismar yok | NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names.nvidia · nvidia resiliency extension · CWE-61 | Yüksek8,4 | — | %0,3 | 16 Ara 2025 |
33İzleyin | CVE-2026-53802İstismar yok | rsync < 3.5.0 Arbitrary File Read via Symlink Followingsamba · rsync · CWE-61 | Yüksek8,4 | — | %0,2 | 13 Ağu 2026 |
33İzleyin | CVE-2026-39860İstismar yok | Nix sandbox escape: file write via symlink at FOD `.tmp` copy destinationlinux · linux kernel · CWE-61 | Yüksek8,4 | — | %0,2 | 8 Nis 2026 |
32İzleyin | CVE-2024-47515İstismar yok | Pagure: generate_archive() follows symbolic links in temporary clonesCWE-61 | Yüksek8,1 | — | %0,6 | 24 Ara 2024 |
32İzleyin | CVE-2026-35525İstismar yok | LiquidJS has a root restriction bypass for partial and layout loading through symlinked templatesliquidjs · liquidjs · CWE-61 | Yüksek8,2 | — | %0,5 | 8 Nis 2026 |
32İzleyin | CVE-2025-10854İstismar yok | Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indicesCWE-61 | Yüksek8,1 | — | %0,5 | 22 Eyl 2025 |
- CVE-2026-5442064Bu hafta
LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP
YüksekCVSS 8,5KEVSilahlaştırılmışEPSS %1litespeedtech · litespeed cpanel plugin14 Haz 2026
- CVE-2024-5466139İzleyin
readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
KritikCVSS 9,8İstismar yokEPSS %1dest-unreach · socat4 Ara 2024
- CVE-2025-2339439İzleyin
daily-backup.sh script in cyrus-imapd allows escalation from cyrus to root
KritikCVSS 9,8İstismar yokEPSS %1suse · opensuse tumbleweed26 May 2025
- CVE-2026-5544738İzleyin
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
KritikCVSS 9,6İstismar yokEPSS %1langflow · langflow23 Haz 2026
- CVE-2025-6893738İzleyin
Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-
KritikCVSS 9,5Kavram kanıtıEPSS %1forgejo · forgejo25 Ara 2025
- CVE-2026-3407837İzleyin
Flatpak has a complete sandbox escape leading to host file access and code execution in the host context
KritikCVSS 9,3İstismar yokEPSS %1flatpak · flatpak7 Nis 2026
- CVE-2025-5534535İzleyin
Unsafe symlink following in restricted workspace-write sandbox leads to RCE
YüksekCVSS 8,8İstismar yokEPSS %113 Ağu 2025
- CVE-2024-2201435İzleyin
An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbol
YüksekCVSS 8,8İstismar yokEPSS %1360totalsecurity · 360 total security15 Nis 2024
- CVE-2026-2797635İzleyin
Zed Extension Sandbox Escape via Tar Symlink Following
YüksekCVSS 8,8İstismar yokEPSS %1zed · zed25 Şub 2026
- CVE-2024-5253535İzleyin
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symboli
YüksekCVSS 8,8İstismar yokEPSS %1dell · supportassist for business pcs25 Ara 2024
- CVE-2024-4541835İzleyin
Zoom Apps for macOS - Symbolic Link Following
YüksekCVSS 8,8İstismar yokEPSS %0zoom · meeting software development kit25 Şub 2025
- CVE-2026-647535İzleyin
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
YüksekCVSS 8,8İstismar yokEPSS %0postgresql · postgresql14 May 2026
- CVE-2026-5674834İzleyin
Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import
YüksekCVSS 8,7İstismar yokEPSS %1cribl · cribl stream27 Tem 2026
- CVE-2026-4193734İzleyin
Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload
YüksekCVSS 8,6İstismar yokEPSS %1givanz · vvveb14 May 2026
- CVE-2025-5780234İzleyin
Airlink's Daemon Symlink Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0airlinklabs · daemon25 Ağu 2025
- CVE-2026-1295834İzleyin
Arbitrary file write in Language Servers for AWS
YüksekCVSS 8,5İstismar yokEPSS %0amazon web services · language servers for aws23 Haz 2026
- CVE-2025-4681034İzleyin
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate
YüksekCVSS 8,5İstismar yokEPSS %0opensuse · tumbleweed2 Eyl 2025
- CVE-2026-4924833İzleyin
OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar
YüksekCVSS 8,3İstismar yokEPSS %1theonedev · onedev18 Haz 2026
- CVE-2025-5256533İzleyin
container escape due to /dev/console mount and related races
YüksekCVSS 8,4İstismar yokEPSS %1linuxfoundation · runc6 Kas 2025
- CVE-2025-3322533İzleyin
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names.
YüksekCVSS 8,4İstismar yokEPSS %0nvidia · nvidia resiliency extension16 Ara 2025
- CVE-2026-5380233İzleyin
rsync < 3.5.0 Arbitrary File Read via Symlink Following
YüksekCVSS 8,4İstismar yokEPSS %0samba · rsync13 Ağu 2026
- CVE-2026-3986033İzleyin
Nix sandbox escape: file write via symlink at FOD `.tmp` copy destination
YüksekCVSS 8,4İstismar yokEPSS %0linux · linux kernel8 Nis 2026
- CVE-2024-4751532İzleyin
Pagure: generate_archive() follows symbolic links in temporary clones
YüksekCVSS 8,1İstismar yokEPSS %124 Ara 2024
- CVE-2026-3552532İzleyin
LiquidJS has a root restriction bypass for partial and layout loading through symlinked templates
YüksekCVSS 8,2İstismar yokEPSS %1liquidjs · liquidjs8 Nis 2026
- CVE-2025-1085432İzleyin
Symlink Following in txtai leads to arbitrary file write when loading untrusted embedding indices
YüksekCVSS 8,1İstismar yokEPSS %022 Eyl 2025