Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-59

45
CRITICAL
691
HIGH
425
MEDIUM
43
LOW
1,232 CVEs · Page 13/25
5.4
CVE-2024-9341

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file pa

5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker t

5.3
CVE-2024-21397

Microsoft Azure File Sync Elevation of Privilege Vulnerability

5.3
CVE-2023-41971

An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows a

4.8
CVE-2024-29069

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap

4.6
CVE-2023-34283

NETGEAR RAX30 USB Share Link Following Information Disclosure Vulnerability. This vulnerability allows physically presen

4.4
CVE-2024-35235

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.8 a

4.4
CVE-2024-35253

Microsoft Azure File Sync Elevation of Privilege Vulnerability

4.4
CVE-2024-45770

A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a

4.4
CVE-2023-20004

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to ove

4.4
CVE-2024-52542

Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with

CVE-2024-52522

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure h

9.9
CVE-2023-6069

Improper Link Resolution Before File Access in GitHub repository froxlor/froxlor prior to 2.1.0.

9.6
CVE-2023-25168

Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively

9.1
CVE-2023-39107

An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows

8.8
CVE-2023-33245

Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution

8.8
CVE-2023-4759

Arbitrary File Overwrite in Eclipse JGit <= 6.6.0 In Eclipse JGit, all versions <= 6.6.0.202305301015-r, a symbolic lin

8.8
CVE-2023-28872

Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privile

8.4
CVE-2023-25152

Wings is Pterodactyl's server control plane. Affected versions are subject to a vulnerability which can be used to creat

8.4
CVE-2023-45159

1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a sym

8.2
CVE-2022-42291

NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experie

8.1
CVE-2022-36943

SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths

8.1
CVE-2023-29351

Windows Group Policy Elevation of Privilege Vulnerability

8.1
CVE-2023-46654

Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory dur

8.1
CVE-2023-28868

Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operati

7.8
CVE-2023-21678

Windows Print Spooler Elevation of Privilege Vulnerability

7.8
CVE-2020-36657

uptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges b

7.8
CVE-2022-45697

Arbitrary File Delete vulnerability in Razer Central before v7.8.0.381 when handling files in the Accounts directory.

7.8
CVE-2023-25145

A link following vulnerability in the scanning function of Trend Micro Apex One agent could allow a local attacker to es

7.8
CVE-2023-25146

A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quaranti

7.8
CVE-2023-25148

A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulner

7.8
CVE-2023-24930

Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

7.8
CVE-2023-26088

In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the loc

7.8
CVE-2023-28892

Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs

7.8
CVE-2023-29343

SysInternals Sysmon for Windows Elevation of Privilege Vulnerability

7.8
CVE-2023-27529

Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulne

7.8
CVE-2023-2939

Insufficient data validation in Installer in Google Chrome on Windows prior to 114.0.5735.90 allowed a local attacker to

7.8
CVE-2023-33865

RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory

7.8
CVE-2023-32012

Windows Container Manager Service Elevation of Privilege Vulnerability

7.8
CVE-2023-32053

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2023-32056

Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability

7.8
CVE-2023-33148

Microsoft Office Elevation of Privilege Vulnerability

7.8
CVE-2023-35320

Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

7.8
CVE-2023-35342

Windows Image Acquisition Elevation of Privilege Vulnerability

7.8
CVE-2023-35353

Connected User Experiences and Telemetry Elevation of Privilege Vulnerability

7.8
CVE-2023-36874 KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

7.8
CVE-2023-35379

Reliability Analysis Metrics Calculation Engine (RACEng) Elevation of Privilege Vulnerability

7.8
CVE-2023-36903

Windows System Assessment Tool Elevation of Privilege Vulnerability

7.8
CVE-2023-38175

Microsoft Windows Defender Elevation of Privilege Vulnerability

7.8
CVE-2019-13689

Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo

Frequently Asked Questions

What is CWE-59?

CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-59?

There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.

How can I protect against CWE-59 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.

Detect CWE-59 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.

Get Started