The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Volume of CVEs assigned to CWE-59 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,607 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30333HIGH RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke | May 9, 2022 | 7.5 | 97 | YES | YES |
CVE-2019-0841HIGH An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. Thi | Apr 9, 2019 | 7.8 | 92 | YES | YES |
CVE-2020-36193HIGH Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. | Jan 18, 2021 | 7.5 | 91 | YES | NO |
CVE-2023-36874HIGH Windows Error Reporting Service Elevation of Privilege Vulnerability | Jul 11, 2023 | 7.8 | 89 | YES | YES |
CVE-2022-21999HIGH Windows Print Spooler Elevation of Privilege Vulnerability | Feb 9, 2022 | 7.8 | 86 | YES | YES |
CVE-2020-0787HIGH An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligen | Mar 12, 2020 | 7.8 | 86 | YES | YES |
CVE-2026-41091HIGH Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | May 20, 2026 | 7.8 | 82 | YES | NO |
CVE-2021-21300HIGH Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/sm | Mar 9, 2021 | 7.5 | 82 | NO | YES |
CVE-2019-1253HIGH An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to g | Sep 11, 2019 | 7.8 | 78 | YES | YES |
CVE-2015-1130HIGH The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors. | Apr 10, 2015 | 7.8 | 78 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.