CWE-59: CWE-59

288
Total CVEs
13
Critical
207
High
7.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
30
2025
90
2024
70
2023
40
2022
20

Top Affected Vendors

1 Microsoft 75
2 Apple 24
3 Trendmicro 13
4 Canonical 6
5 Dell 6
6 Google 5
7 Fedoraproject 4
8 Avast 4
9 Mcafee 4
10 Debian 4

All CWE-59 CVEs (288)

CVE-2025-15314
5.5

CVE-2025-15314 is an arbitrary file deletion vulnerability in Tanium's end-user-cx component that allows authenticated attackers to delete files on af...

Feb 10, 2026
CVE-2025-15318
5.5

CVE-2025-15318 is an arbitrary file deletion vulnerability in Tanium's Endpoint Configuration Toolset Solution that allows authenticated attackers to ...

Feb 9, 2026
CVE-2025-13154
5.5

An authenticated local user can exploit this improper link following vulnerability in Lenovo Vantage's SmartPerformanceAddin to delete arbitrary files...

Jan 14, 2026
CVE-2025-43461
5.5

This CVE describes a macOS vulnerability where improper symlink validation could allow an application to bypass file system protections and access sen...

Dec 12, 2025
CVE-2025-43381
5.5

This CVE describes a macOS vulnerability where improper symlink handling allows malicious applications to delete protected user data. It affects macOS...

Dec 12, 2025
CVE-2025-59510
5.5

This vulnerability in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to create symbolic links that cause the service t...

Nov 11, 2025
CVE-2025-43394
5.5

A symlink handling vulnerability in macOS allows applications to bypass file system protections and access sensitive user data. This affects macOS Seq...

Nov 4, 2025
CVE-2025-43379
5.5

This CVE describes a symlink validation vulnerability in Apple operating systems that could allow malicious apps to bypass file system protections and...

Nov 4, 2025
CVE-2025-43288
5.5

A macOS vulnerability allows malicious applications to bypass Privacy preferences by exploiting improper symlink validation. This affects macOS system...

Nov 4, 2025
CVE-2025-58373
5.5

This vulnerability in Roo Code allows attackers with write access to bypass .rooignore file protections using symbolic links, potentially exposing sen...

Sep 5, 2025
CVE-2024-54554
5.5

This CVE describes a macOS vulnerability where improper symlink handling allows applications to access sensitive user data. It affects macOS systems b...

Aug 29, 2025
CVE-2025-30642
5.5

A link following vulnerability in Trend Micro Deep Security 20.0 agents allows local attackers to create denial of service conditions. This affects sy...

Jun 17, 2025
CVE-2025-0913
5.5

This vulnerability involves inconsistent symlink handling in Go's os.OpenFile function when using O_CREATE|O_EXCL flags on Windows versus Unix systems...

Jun 11, 2025
CVE-2025-31198
5.5

This CVE describes a path handling vulnerability in macOS that allows improper symlink validation. Attackers could potentially exploit this to access ...

May 29, 2025
CVE-2025-24278
5.5

A symlink validation vulnerability in macOS allows applications to bypass file system protections and access protected user data. This affects macOS V...

Mar 31, 2025
CVE-2025-24104
5.5

This vulnerability allows an attacker to modify protected system files on iOS/iPadOS devices by restoring a maliciously crafted backup file containing...

Jan 27, 2025
CVE-2025-21274
5.5

This vulnerability in Windows Event Tracing allows attackers to cause a denial of service condition by sending specially crafted requests. It affects ...

Jan 14, 2025
CVE-2024-44211
5.5

This vulnerability allows malicious applications to bypass symlink validation and access sensitive user data on macOS. It affects macOS systems before...

Dec 20, 2024
CVE-2024-7235
5.5

This vulnerability in AVG AntiVirus Free allows local attackers to create a denial-of-service condition by exploiting a symbolic link handling flaw in...

Nov 22, 2024
CVE-2024-44264
5.5

This macOS vulnerability allows malicious applications to create symbolic links to protected disk regions, potentially bypassing security restrictions...

Oct 28, 2024
CVE-2024-44178
5.5

This CVE describes a symlink validation vulnerability in macOS that allows an application to bypass file system protections and modify restricted area...

Sep 17, 2024
CVE-2024-44131
5.5

This vulnerability allows malicious apps to bypass symlink validation and access sensitive user data on Apple devices. It affects iOS, iPadOS, and mac...

Sep 17, 2024
CVE-2024-9341
5.4

This vulnerability in Go's containers/common library allows attackers to exploit symbolic links when FIPS mode is enabled, potentially mounting sensit...

Oct 1, 2024
CVE-2026-22701
5.3

This CVE describes a TOCTOU race condition vulnerability in the filelock Python package's SoftFileLock implementation. Attackers with local filesystem...

Jan 10, 2026
CVE-2023-41971
5.3

This vulnerability in Zscaler Client Connector on Windows allows attackers to overwrite system files through improper link resolution. It affects all ...

May 2, 2024
CVE-2025-15328
5.0

CVE-2025-15328 is an improper link resolution vulnerability in Tanium Enforce that could allow attackers to access files they shouldn't be able to rea...

Feb 5, 2026
CVE-2025-64437
5.0

This CVE allows attackers who control the virt-launcher pod filesystem to change ownership of arbitrary host node files to the unprivileged UID 107 us...

Nov 7, 2025
CVE-2025-41421
4.7

This vulnerability allows attackers with local, unprivileged access to escalate privileges by exploiting improper symbolic link handling in TeamViewer...

Oct 1, 2025
CVE-2023-34283
4.6

This vulnerability allows physically present attackers to access arbitrary files on NETGEAR RAX30 routers by exploiting improper symbolic link handlin...

May 3, 2024
CVE-2026-22702
4.5

This CVE describes a TOCTOU vulnerability in virtualenv that allows local attackers to exploit race conditions during directory creation. Attackers ca...

Jan 10, 2026
CVE-2025-24136
4.4

This macOS vulnerability allows malicious applications to create symbolic links to protected disk regions, potentially bypassing security restrictions...

Jan 27, 2025
CVE-2024-35253
4.4

This vulnerability in Microsoft Azure File Sync allows authenticated attackers to elevate privileges within the Azure File Sync service. It affects or...

Jun 11, 2024
CVE-2025-43395
3.3

This macOS vulnerability allows malicious applications to bypass symlink protections and access protected user data. It affects macOS systems before s...

Nov 4, 2025
CVE-2026-26225
N/A

Intego Personal Backup for macOS contains a local privilege escalation vulnerability where non-privileged users can write malicious backup task files ...

Feb 12, 2026
CVE-2025-15541
N/A

This vulnerability in TP-Link VX800v v1.0 SFTP service allows authenticated attackers on the same network to create symbolic links that bypass directo...

Jan 29, 2026
CVE-2025-15543
N/A

This vulnerability allows an attacker with physical access to a TP-Link VX800v v1.0 device to read system files by connecting a specially crafted USB ...

Jan 29, 2026
CVE-2025-34352
N/A

This vulnerability allows local low-privileged attackers to achieve arbitrary file writes or deletions on Windows systems by exploiting insecure tempo...

Dec 2, 2025
CVE-2025-12418
N/A

A symlink vulnerability in Revenera InstallShield allows local administrators to cause denial of service during uninstallation. When removing a user-w...

Nov 7, 2025

About CWE-59 (CWE-59)

Our database tracks 288 CVEs classified as CWE-59, with 13 rated critical and 207 rated high severity. The average CVSS score for CWE-59 vulnerabilities is 7.4.

External reference: View CWE-59 on MITRE CWE →

Monitor CWE-59 Vulnerabilities

Get alerted when new CWE-59 CVEs affect your infrastructure.

Start Monitoring Free