Vulnerabilities (CVE)

Filtered by CWE-59
Total 1728 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-21322 1 Microsoft 1 Pc Manager 2026-06-17 N/A 7.8 HIGH
Microsoft PC Manager Elevation of Privilege Vulnerability
CVE-2025-21274 1 Microsoft 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more 2026-06-17 N/A 5.5 MEDIUM
Windows Event Tracing Denial of Service Vulnerability
CVE-2025-21204 1 Microsoft 15 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 12 more 2026-06-17 N/A 7.8 HIGH
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVE-2025-21195 1 Microsoft 1 Azure Service Fabric 2026-06-17 N/A 6.0 MEDIUM
Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.
CVE-2025-21188 1 Microsoft 1 Azure Network Watcher 2026-06-17 N/A 6.0 MEDIUM
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
CVE-2025-20003 2026-06-17 N/A 8.2 HIGH
Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2025-1697 1 Hp 1 Touchpoint Analytics Service 2026-06-17 N/A 7.8 HIGH
A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products with versions prior to 4.2.2439. This vulnerability could potentially allow a local attacker to escalate privileges. HP is providing software updates to mitigate this potential vulnerability.
CVE-2025-1683 1 1e 1 Platform 2026-06-17 N/A 7.8 HIGH
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.
CVE-2025-1079 3 Apple, Google, Linux 3 Macos, Web Designer, Linux Kernel 2026-06-17 N/A 7.8 HIGH
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
CVE-2025-15543 1 Tp-link 2 Vx800v, Vx800v Firmware 2026-06-17 N/A 4.6 MEDIUM
Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem contents, giving an attacker with physical access read‑only access to system files.
CVE-2025-15541 1 Tp-link 2 Vx800v, Vx800v Firmware 2026-06-17 N/A 6.3 MEDIUM
Improper link resolution in the VX800v v1.0 SFTP service allows authenticated adjacent attackers to use crafted symbolic links to access system files, resulting in high confidentiality impact and limited integrity risk.
CVE-2025-15328 1 Enforce 1 Enforce 2026-06-17 N/A 5.0 MEDIUM
Tanium addressed an improper link resolution before file access vulnerability in Enforce.
CVE-2025-15324 1 Tanium 1 Engage 2026-06-17 N/A 6.6 MEDIUM
Tanium addressed a documentation issue in Engage.
CVE-2025-15319 1 Tanium 1 Patch Endpoint Tools 2026-06-17 N/A 7.8 HIGH
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
CVE-2025-15318 1 Tanium 1 End-user Notifications 2026-06-17 N/A 5.5 MEDIUM
Tanium addressed an arbitrary file deletion vulnerability in End-User Notifications Endpoint Tools.
CVE-2025-15314 1 Tanium 1 End-user-cx 2026-06-17 N/A 5.5 MEDIUM
Tanium addressed an arbitrary file deletion vulnerability in end-user-cx.
CVE-2025-15313 1 Tanium 1 Euss 2026-06-17 N/A 5.5 MEDIUM
Tanium addressed an arbitrary file deletion vulnerability in Tanium EUSS.
CVE-2025-15310 1 Tanium 2 Endpoint Configuration Toolset Solution, Patch Endpoint Tools 2026-06-17 N/A 7.8 HIGH
Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools.
CVE-2025-14693 2026-06-17 6.5 MEDIUM 6.2 MEDIUM
A vulnerability has been found in Ugreen DH2100+ up to 5.3.0. This affects an unknown function of the component USB Handler. Such manipulation leads to symlink following. The attack can be executed directly on the physical device. The exploit has been disclosed to the public and may be used. It is suggested to upgrade the affected component.
CVE-2025-13154 2026-06-17 N/A 5.5 MEDIUM
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.