Cyber Posture

CWE · MITRE source

CWE-59Improper Link Resolution Before File Access ('Link Following')

Abstraction: Base · CVEs in our corpus: 1,483

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Last updated: 20 May 2026 08:06 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-30333 KEV9.17.50.92792022-05-09
CVE-2019-0841 KEV8.57.80.82652019-04-09
CVE-2022-21999 KEV7.97.80.71512022-02-09
CVE-2020-36193 KEV7.87.50.71152021-01-18
CVE-2023-36874 KEV7.77.80.68832023-07-11
CVE-2020-0787 KEV7.17.80.59282020-03-12
CVE-2024-57728 KEV UPD7.07.20.58822025-01-15
CVE-2024-320026.69.00.79592024-05-14
CVE-2024-281855.910.00.65022024-04-18
CVE-2023-400285.64.90.77612023-08-15
CVE-2024-281895.510.00.57582024-04-18
CVE-2019-1069 KEV5.47.80.30082019-06-12
CVE-2020-0683 KEV5.47.80.31062020-02-11
CVE-2025-60710 KEV5.47.80.29872025-11-11
CVE-2021-213005.38.00.61882021-03-09
CVE-2024-206565.37.80.62742024-01-09
CVE-2019-1253 KEV5.27.80.27732019-09-11
CVE-2015-1130 KEV UPD5.07.80.23422015-04-10
CVE-2016-6664 UPD4.77.00.54392016-12-13
CVE-2024-536914.68.80.48052024-12-06
CVE-2024-504044.48.80.44292024-12-06
CVE-2019-1064 KEV4.37.80.11822019-06-12
CVE-2019-10021014.26.40.49272019-04-01
CVE-2019-1315 KEV4.07.80.07602019-10-10
CVE-2017-26193.97.50.40672018-03-12