Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-59

45
CRITICAL
691
HIGH
425
MEDIUM
43
LOW
1,232 CVEs · Page 6/25
5.1
CVE-2026-55443

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components

5.0
CVE-2025-15328

Tanium addressed an improper link resolution before file access vulnerability in Enforce.

5.0
CVE-2026-6891

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a l

5.0
CVE-2026-6892

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with

5.0
CVE-2026-54055

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability ex

5.0
CVE-2026-12391

An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with

4.9
CVE-2026-46464

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

4.8
CVE-2026-54706

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

4.7
CVE-2026-21517

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to e

4.7
CVE-2026-27456

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vuln

4.7
CVE-2026-35359

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass

4.7
CVE-2026-40977

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'

4.7
CVE-2026-5061

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha

4.7
CVE-2026-14361

The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template

4.7
CVE-2026-53797

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an

4.7
CVE-2026-53800

rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta

4.6
CVE-2025-15543

Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co

4.5
CVE-2026-22702

virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-

4.4
CVE-2026-7397

A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path

4.4
CVE-2026-44269

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

4.4
CVE-2026-46468

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

4.4
CVE-2026-16130

A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of th

4.4
CVE-2026-18508

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin

4.3
CVE-2026-17459

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter

4.3
CVE-2026-70427

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names du

4.2
CVE-2026-8784

A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file c

4.2
CVE-2026-55086

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/Exp

4.0
CVE-2026-65069

Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_

3.8
CVE-2026-64614

Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o

3.8
CVE-2026-64617

Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65061

Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65062

Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EX

3.8
CVE-2026-65063

Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EX

3.8
CVE-2026-65064

Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65066

Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_E

3.8
CVE-2026-65067

Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.8
CVE-2026-65068

Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_

3.5
CVE-2026-35400

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project

3.3
CVE-2026-32020

OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symb

3.3
CVE-2026-14699

A weakness has been identified in zcaceres markdownify-mcp up to 1.1.0. The affected element is the function assertPathA

3.3
CVE-2026-61858

ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to mis

3.3
CVE-2026-61859

ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operatio

3.3
CVE-2026-64615

Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL o

3.3
CVE-2026-64616

Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL

3.2
CVE-2026-44220

ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function i

3.1
CVE-2026-14966

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa

2.5
CVE-2026-17435

File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When th

2.2
CVE-2026-12567

The github_workflows module constructs local directory paths from user-controlled repository names without validating fo

2.0
CVE-2026-45403

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

CVE-2025-53594

A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user ac

Frequently Asked Questions

What is CWE-59?

CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-59?

There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.

How can I protect against CWE-59 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.

Detect CWE-59 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.

Get Started