Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-59

Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,607
Assigned CVEs
37th
Commonality Rank
6.5
Avg CVSS
1.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-59 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 1998
28 years ago
Most Recent CVE
Jul 24, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,607 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-30333HIGH
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke
May 9, 20227.597YESYES
CVE-2019-0841HIGH
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. Thi
Apr 9, 20197.892YESYES
CVE-2020-36193HIGH
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
Jan 18, 20217.591YESNO
CVE-2023-36874HIGH
Windows Error Reporting Service Elevation of Privilege Vulnerability
Jul 11, 20237.889YESYES
CVE-2022-21999HIGH
Windows Print Spooler Elevation of Privilege Vulnerability
Feb 9, 20227.886YESYES
CVE-2020-0787HIGH
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligen
Mar 12, 20207.886YESYES
CVE-2026-41091HIGH
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
May 20, 20267.882YESNO
CVE-2021-21300HIGH
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/sm
Mar 9, 20217.582NOYES
CVE-2019-1253HIGH
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to g
Sep 11, 20197.878YESYES
CVE-2015-1130HIGH
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.
Apr 10, 20157.878YESYES
View all 1,607 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
13%
19%
5.0-5.9
20%
16%
6.0-6.9
40%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
23 CVEs
1.4% of CVEs· 93rd percentile
Metasploit
13 CVEs
0.8% of CVEs· 86th percentile
Nuclei
1 CVE
0.1% of CVEs· 77th percentile
ExploitDB
55 CVEs
3.4% of CVEs· 93rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products