Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-59

45
CRITICAL
691
HIGH
425
MEDIUM
43
LOW
1,232 CVEs · Page 7/25
CVE-2026-26225

Intego Personal Backup, a macOS backup utility that allows users to create scheduled backups and bootable system clones,

CVE-2026-42795

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th

CVE-2026-11940

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference

CVE-2026-52811

Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only

CVE-2026-53535

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf

CVE-2026-8170

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize pat

CVE-2026-12503

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-

CVE-2026-67433

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In

CVE-2026-71476

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx sel

CVE-2025-30240

The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By

CVE-2026-0291

An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Li

CVE-2026-17106

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers

CVE-2026-71493

Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, p

CVE-2026-65647

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as r

CVE-2026-56651

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open

9.8
CVE-2025-30457

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1

9.8
CVE-2025-43220

This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6,

8.8
CVE-2024-10986

GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This fu

8.8
CVE-2024-12390

A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application suppo

8.8
CVE-2025-47181

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a

8.8
CVE-2025-41666

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write an

8.8
CVE-2025-41667

A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read

8.8
CVE-2025-41668

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-pro

8.8
CVE-2025-49739

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to eleva

8.6
CVE-2025-67487

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and be

8.5
CVE-2025-23267

NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could

8.4
CVE-2025-34191

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192

8.4
CVE-2023-53973

Zillya Total Security 3.0.2367.0 contains a privilege escalation vulnerability that allows low-privileged users to copy

8.2
CVE-2025-20003

Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may

8.1
CVE-2025-66626

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version

8.0
CVE-2025-48384 KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-

7.8
CVE-2025-0413

Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability a

7.8
CVE-2025-21322

Microsoft PC Manager Elevation of Privilege Vulnerability

7.8
CVE-2025-21373

Windows Installer Elevation of Privilege Vulnerability

7.8
CVE-2025-21420

Windows Disk Cleanup Tool Elevation of Privilege Vulnerability

7.8
CVE-2025-1683

Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an

7.8
CVE-2025-29795

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a

7.8
CVE-2025-21204

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to

7.8
CVE-2025-27727

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to ele

7.8
CVE-2025-1697

A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products

7.8
CVE-2025-3224

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr

7.8
CVE-2024-13759

Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attack

7.8
CVE-2024-13944

Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.

7.8
CVE-2024-13959

Link Following Local Privilege Escalation Vulnerability in TuneupSvc.exe in AVG TuneUp 24.2.16593.9844 on Windows allows

7.8
CVE-2024-13960

Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Wi

7.8
CVE-2024-13961

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Avast Cleanup Premium Version 24.2.16593.17810 o

7.8
CVE-2024-13962

Link Following Local Privilege Escalation Vulnerability in TuneupSvc in Gen Digital Inc. Avast Cleanup Premium Version 2

7.8
CVE-2024-9524

Link Following Local Privilege Escalation Vulnerability in System Speedup Service in Avira Operations GmbH Avira Prime V

7.8
CVE-2025-1079

Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

7.8
CVE-2025-29975

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to

Frequently Asked Questions

What is CWE-59?

CWE-59 (CWE-59) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-59?

There are 1,879 CVE records associated with CWE-59 in our database. Of these, 45 are critical severity, 691 are high severity, and 425 are medium severity.

How can I protect against CWE-59 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-59 using AI-powered security agents.

Detect CWE-59 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-59 vulnerabilities across your infrastructure.

Get Started