Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-61 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 30 | 30 | 1 |
▂█▆▄
2026-05 2 · 2026-06 13 · 2026-07 10 · 2026-08 5
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-54420 | 8.5 | 71.0 | KEV | LiteSpeed cPanel Plugin |
| CVE-2026-49248 | 8.3 | 44.7 | — | OneDev: RCE through absolute-path symlink following allows low-privileged users to over… |
| CVE-2026-56748 | 8.7 | 44.5 | — | Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import |
| CVE-2026-55447 | 9.6 | 38.8 | — | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit |
| CVE-2026-52811 | 9.0 | 37.9 | — | Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym |
| CVE-2026-41937 | 8.6 | 33.7 | — | Vvveb < 1.0.8.3 Unrestricted File Upload RCE via Plugin Upload |
| CVE-2026-56876 | 8.6 | 32.4 | — | extract-zip unvalidated symlink path traversal |
| CVE-2026-55686 | 5.3 | 30.7 | — | Podman: WORKDIR symlink traversal vulnerability |
| CVE-2026-62992 | 6.9 | 29.6 | — | Smarty: Symlink path traversal out of trusted directories |
| CVE-2026-17459 | 2.1 | 24.8 | — | perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink |
| CVE-2026-5223 | 6.5 | 22.1 | — | Crates in third party registries can override the cached source of other crates |
| CVE-2026-12958 | 8.5 | 17.3 | — | Arbitrary file write in Language Servers for AWS |
| CVE-2026-39822 | 7.8 | 14.4 | — | Root escape via symlink plus trailing slash in os |
| CVE-2026-53489 | 8.2 | 8.6 | — | containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint re… |
| CVE-2026-41579 | 3.3 | 8.6 | — | runc: Malicious image with /dev symlink can trigger limited host filesystem integrity v… |
| CVE-2026-47766 | 5.1 | 5.8 | — | crun follows rootfs /dev symlink while creating default devices |
| CVE-2026-56815 | 7.4 | 5.2 | — | — |
| CVE-2026-47763 | 6.8 | 4.8 | — | pdm: Project-Local State and Config Writes Follow Symlinks |
| CVE-2025-43278 | 5.5 | 4.8 | — | — |
| CVE-2026-13201 | 7.3 | 4.5 | — | Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enab… |
| Vendor | CVEs |
|---|---|
| red hat | 3 |
| amazon web services | 1 |
| apple | 1 |
| containerd | 1 |
| containers | 1 |
| cribl | 1 |
| dell | 1 |
| givanz | 1 |
| go standard library | 1 |
| gogs | 1 |
| huggingface | 1 |
| langflow-ai | 1 |
| litespeed technologies | 1 |
| max-mapper | 1 |
| moby | 1 |