Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) — Vulnerability Class 418

418 vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-5718 AXIS OS 安全漏洞 — AXIS OS 6.8 Medium2025-11-11
CVE-2025-11578 Pre-Receive Hook Path Collision Vulnerability in GitHub Enterprise Server Allowing Privilege Escalation — Enterprise Server 7.2 -2025-11-10
CVE-2025-64437 KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes — kubevirt 5.0 Medium2025-11-07
CVE-2025-12418 Potential Denial of Service in Supported Versions of Revenera InstallShield — InstallShield 4.4 -2025-11-07
CVE-2025-9870 Razer Synapse 3 RazerPhilipsHueUninstall Link Following Local Privilege Escalation Vulnerability — Synapse 3 7.8AIHighAI2025-10-29
CVE-2025-9871 Razer Synapse 3 Chroma Connect Link Following Local Privilege Escalation Vulnerability — Synapse 3 7.8AIHighAI2025-10-29
CVE-2025-9869 Razer Synapse 3 Macro Module Link Following Local Privilege Escalation Vulnerability — Synapse 3 7.8AIHighAI2025-10-29
CVE-2025-12341 ermig1979 AntiDupl Delete Duplicate Image AntiDupl.NET.WinForms.exe link following — AntiDupl 7.8 High2025-10-28
CVE-2025-26625 Git LFS may write to arbitrary files via crafted symlinks — git-lfs 8.1AIHighAI2025-10-17
CVE-2025-59241 Windows Health and Optimized Experiences Elevation of Privilege Vulnerability — Windows 11 Version 24H2 7.8 High2025-10-14
CVE-2025-59281 Xbox Gaming Services Elevation of Privilege Vulnerability — Xbox Gaming Services 7.8 High2025-10-14
CVE-2025-55247 .NET Elevation of Privilege Vulnerability — .NET 8.0 7.3 High2025-10-14
CVE-2025-62363 yt-grabber-tui allows arbitrary code execution via configurable yt-dlp path — YtGrabber-TUI 7.8 High2025-10-13
CVE-2025-62364 text-generation-webui allows arbitrary file read via symbolic link upload — text-generation-webui 6.2 Medium2025-10-13
CVE-2025-9968 ASUS Armoury Crate 安全漏洞 — Armoury Crate 7.8AIHighAI2025-10-13
CVE-2025-11462 Local Privilege Escalation Vulnerability in AWS Client VPN macOS Client — Client VPN 7.8 High2025-10-07
CVE-2025-41421 Privilege Escalation via Symbolic Link Spoofing in TeamViewer Client — Full Client 4.7 Medium2025-10-01
CVE-2025-34191 Vasion Print (formerly PrinterLogic) Arbitrary File Write as Root via Response Path Symlink Follow — Print Virtual Appliance Host 7.1 -2025-09-19
CVE-2025-34194 Vasion Print (formerly PrinterLogic) Local Privilege Escalation via Insecure Temporary File Handling — Print Virtual Appliance Host 7.8 -2025-09-19
CVE-2025-55317 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability — Microsoft AutoUpdate for Mac 7.8 High2025-09-09
CVE-2025-55245 Xbox Gaming Services Elevation of Privilege Vulnerability — Xbox Gaming Services 7.8 High2025-09-09
CVE-2025-58373 Roo Code: Symlink-bypass of .rooignore can lead to unintended file disclosure — Roo-Code 5.5 Medium2025-09-05
CVE-2025-43726 Dell Alienware Command Center 后置链接漏洞 — Alienware Command Center 5.x (AWCC) 6.7 Medium2025-09-02
CVE-2025-57749 n8n has a symlink traversal vulnerability in "Read/Write File" node allows access to restricted files — n8n 6.5 Medium2025-08-20
CVE-2025-8612 AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability — Backupper Workstation 7.3 -2025-08-20
CVE-2025-5296 Schneider Electric SESU 后置链接漏洞 — SESU 7.3 High2025-08-18
CVE-2025-8959 HashiCorp go-getter Vulnerable to Arbitrary Read through Symlink Attack — Shared library 7.5 High2025-08-15
CVE-2025-43490 HP Hotkey Support – Escalation of Privilege — HP Hotkey Support Software 7.8AIHighAI2025-08-15
CVE-2025-55188 7-Zip 安全漏洞 — 7-Zip 3.6 Low2025-08-08
CVE-2025-54798 tmp does not restrict arbitrary temporary file / directory write via symbolic link `dir` parameter — node-tmp 2.5 Low2025-08-07

Vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) represent 418 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.