Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-59 · Link followingDefinition on MITRE ↗Clear

16 results

CVE-2026-41091
2026-05-20
Microsoft Defender Link Following Vulnerability
Microsoft

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

CWE-59 · Link following
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-06-03
CVE-2025-60710
2026-04-13
Microsoft Windows Link Following VulnerabilityRansomware
Microsoft

Microsoft Windows contains a link following vulnerability that allows for privilege escalation

CWE-59 · Link following
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2026-04-27
CVE-2025-48384
2025-08-25
Git Link Following Vulnerability
Git

Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.

CWE-59 · Link followingCWE-436
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please seeaccess.redhat.comalas.aws.amazon.comlinux.oracle.commsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-09-15
CVE-2025-21391
2025-02-11
Microsoft Windows Storage Link Following Vulnerability
Microsoft

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.

CWE-59 · Link following
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2025-03-04
CVE-2023-36874
2023-07-11
Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability
Microsoft

Microsoft Windows Error Reporting Service contains an unspecified vulnerability that allows for privilege escalation.

CWE-59 · Link following
Refsmsrc.microsoft.comnvd.nist.gov
Federal remediation due 2023-08-01
CVE-2020-36193
2022-08-25
PEAR Archive_Tar Improper Link Resolution Vulnerability
PEAR

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

CWE-22 · Path traversalCWE-59 · Link following
Refsgithub.comnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2022-30333
2022-08-09
RARLAB UnRAR Directory Traversal VulnerabilityRansomware
RARLAB

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

CWE-22 · Path traversalCWE-59 · Link following
RefsVulnerability updated with version 6.12. Accessing link will download update informationnvd.nist.gov
Federal remediation due 2022-08-30
CVE-2019-1385
2022-05-23
Microsoft Windows AppX Deployment Extensions Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2019-1130
2022-05-23
Microsoft Windows AppX Deployment Service Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-06-13
CVE-2019-1315
2022-03-15
Microsoft Windows Error Reporting Manager Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1253
2022-03-15
Microsoft Windows AppX Deployment Server Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1129
2022-03-15
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1069
2022-03-15
Microsoft Task Scheduler Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-1064
2022-03-15
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2019-0841
2022-03-15
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation VulnerabilityRansomware
Microsoft

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-04-05
CVE-2020-0787
2022-01-28
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management VulnerabilityRansomware
Microsoft

Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.

CWE-269 · Improper privilege managementCWE-59 · Link following
Refsnvd.nist.gov
Federal remediation due 2022-07-28