Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Priv
Improper Link Resolution Before File Access ('Link Following') vulnerability in yrutschle sslh.This issue affects sslh:
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio
An issue in Cato Networks' CatoClient for Linux, before version 5.5, allows a local attacker to escalate privileges to r
A potential security vulnerability has been identified in the HPAudioAnalytics service included in the HP Hotkey Support
A link following vulnerability exists in the UnifyScanner component of Armoury Crate. This vulnerability may be triggere
Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git re
Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2,
JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Wi
Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.
mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction.
A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow rem
qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Att
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed cont
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, reposito
Xbox Gaming Services Elevation of Privilege Vulnerability
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escala
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow re
A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
Azure Monitor Agent Elevation of Privilege Vulnerability
Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerab
WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action
Visual Studio Elevation of Privilege Vulnerability
PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command executi
An agent link vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileg
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privilege
An anti-spyware engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate pri
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privilege
An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the upda
A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload S
This issue was addressed with improved handling of symlinks. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvO
Microsoft Office Elevation of Privilege Vulnerability
Windows Authentication Elevation of Privilege Vulnerability
Microsoft Install Service Elevation of Privilege Vulnerability
Microsoft Brokering File System Elevation of Privilege Vulnerability
G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers
VIPRE Antivirus Plus Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers
VIPRE Antivirus Plus TelFileTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows
VIPRE Antivirus Plus FPQuarTransfer Link Following Local Privilege Escalation Vulnerability. This vulnerability allows l
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows loca
Avast Premium Security Sandbox Protection Link Following Privilege Escalation Vulnerability. This vulnerability allows l
G DATA Total Security GDBackupSvc Service Link Following Local Privilege Escalation Vulnerability. This vulnerability al
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows loca
Parallels Desktop Updater Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac
An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started