Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones,
Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize pat
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx sel
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Li
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers
Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, p
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as r
Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6,
GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This fu
A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application suppo
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a
A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write an
A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read
A low privileged remote attacker with file access can replace a critical file or folder used by the service security-pro
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to eleva
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and be
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192
Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy
Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability a
Microsoft PC Manager Elevation of Privilege Vulnerability
Windows Installer Elevation of Privilege Vulnerability
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele
A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr
Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64 allows local attack
Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.
Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows
Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Wi
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 o
Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 2
Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime V
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to
Frequently Asked Questions
What is CWE-59?
CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-59?
There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.
How can I protect against CWE-59 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.
Detect CWE-59 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.
Get Started