Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Datasets Symlink-following Arbitrary File Write via Extractor.extract()
Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys
LPE from suricata user to root due to chown in %post in suricata packaging
zcaceres markdownify-mcp Markdownify.ts assertPathAllowed symlink
containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
extract-zip unvalidated symlink path traversal
Podman: WORKDIR symlink traversal vulnerability
Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher
Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption
Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Arbitrary file write in Language Servers for AWS
pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home
OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar
LiteSpeed cPanel plugin before 2
Moby: Race condition in docker cp allows bind mount redirection to host path
Crates in third party registries can override the cached source of other crates
npitre cramfs-tools cramfsck.c change_file_status symlink
Showing 1 - 20 of 1,000+ results