Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) — Vulnerability Class 418

418 vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-36611 Dell Security Management Server和Dell Encryption 后置链接漏洞 — Encryption 7.3 High2025-07-30
CVE-2025-23267 NVIDIA Container Toolkit 后置链接漏洞 — Container Toolkit 8.5 High2025-07-17
CVE-2025-7012 Cato Networks Linux Client Local Privilege Escalation via Symlink — Cato Client 7.8AIHighAI2025-07-13
CVE-2025-49739 Visual Studio Elevation of Privilege Vulnerability — Microsoft Visual Studio 2015 Update 3 8.8 High2025-07-08
CVE-2025-49738 Microsoft PC Manager Elevation of Privilege Vulnerability — Microsoft PC Manager 7.8 High2025-07-08
CVE-2025-49680 Windows Performance Recorder (WPR) Denial of Service Vulnerability — Windows 10 Version 1507 7.3 High2025-07-08
CVE-2025-48820 Windows AppX Deployment Service Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-07-08
CVE-2025-48799 Windows Update Service Elevation of Privilege Vulnerability — Windows 10 Version 1607 7.8 High2025-07-08
CVE-2025-21195 Azure Service Fabric Runtime Elevation of Privilege Vulnerability — Service Fabric 6.0 Medium2025-07-08
CVE-2025-41668 Phoenix Contact: File access due to the replacement of a critical file used by the service security-profile — AXC F 1152 8.8 High2025-07-08
CVE-2025-41667 Phoenix Contact: File access due to the replacement of a critical file used by the arp-preinit script — AXC F 1152 8.8 High2025-07-08
CVE-2025-41666 Phoenix Contact: File access due to the replacement of a critical file used by the watchdog — AXC F 1152 8.8 High2025-07-08
CVE-2025-53109 Model Context Protocol Servers Vulnerable to Path Validation Bypass via Prefix Matching and Symlink Handling — servers 4.3AIMediumAI2025-07-02
CVE-2025-3771 Trellix System Information Reporter 安全漏洞 — System Information Reporter 7.1AIHighAI2025-06-26
CVE-2025-52936 Improper Link Resolution Before File Access vulnerability in yrutschle/sslh — sslh 8.2AIHighAI2025-06-23
CVE-2025-30642 Trend Micro Deep Security 安全漏洞 — Trend Micro Deep Security 5.5 Medium2025-06-17
CVE-2025-30641 Trend Micro Deep Security 安全漏洞 — Trend Micro Deep Security 7.8 High2025-06-17
CVE-2025-30640 Trend Micro Deep Security 安全漏洞 — Trend Micro Deep Security 7.8 High2025-06-17
CVE-2025-33075 Windows Installer Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.8 High2025-06-10
CVE-2025-32721 Windows Recovery Driver Elevation of Privilege Vulnerability — Windows 10 Version 1507 7.3 High2025-06-10
CVE-2025-5474 2BrightSparks SyncBackFree Link Following Local Privilege Escalation Vulnerability — SyncBackFree 7.3AIHighAI2025-06-06
CVE-2024-11857 Realtek Bluetooth HCI Adaptor - Privilege Escalation — Bluetooth HCI Adaptor 7.8 High2025-06-02
CVE-2025-47181 Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability — Microsoft Edge (Chromium-based) Updater 8.8 High2025-05-22
CVE-2025-2102 HYPR Passwordless 安全漏洞 — Passwordless 7.8AIHighAI2025-05-21
CVE-2025-3908 OpenVPN 安全漏洞 — OpenVPN 3 Linux 5.5AIMediumAI2025-05-19
CVE-2025-4211 Improper Link Resolution Before File Access in QFileSystemEngine on Windows — Qt 8.4AIHighAI2025-05-16
CVE-2025-29837 Windows Installer Information Disclosure Vulnerability — Windows 10 Version 1507 5.5 Medium2025-05-13
CVE-2025-29975 Microsoft PC Manager Elevation of Privilege Vulnerability — Microsoft PC Manager 7.8 High2025-05-13
CVE-2025-22247 Insecure file handling vulnerability — VMware Tools 6.1 Medium2025-05-12
CVE-2024-9524 Privilege Escalation Vulnerability in Avira Prime Version 1.1.96.2 — Prime 7.8 High2025-05-09

Vulnerabilities classified as CWE-59 (在文件访问前对链接解析不恰当(链接跟随)) represent 418 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.