Cyber Posture

CWE · MITRE source

CWE-59Improper Link Resolution Before File Access ('Link Following')

Abstraction: Base · CVEs in our corpus: 1,465

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2022-30333 KEV9.17.50.92812022-05-09
CVE-2019-0841 KEV8.57.80.82652019-04-09
CVE-2022-21999 KEV8.07.80.73932022-02-09
CVE-2020-36193 KEV7.87.50.71152021-01-18
CVE-2023-36874 KEV7.77.80.68832023-07-11
CVE-2020-0787 KEV7.37.80.61772020-03-12
CVE-2024-57728 KEV7.07.20.59332025-01-15
CVE-2024-320026.69.00.79592024-05-14
CVE-2024-281855.910.00.65022024-04-18
CVE-2023-400285.64.90.77612023-08-15
CVE-2019-1253 KEV5.57.80.31942019-09-11
CVE-2021-213005.58.00.64462021-03-09
CVE-2024-281895.510.00.57582024-04-18
CVE-2019-1069 KEV5.47.80.30082019-06-12
CVE-2020-0683 KEV5.47.80.31062020-02-11
CVE-2024-206565.37.80.62742024-01-09
CVE-2025-60710 KEV5.37.80.29722025-11-11
CVE-2015-1130 KEV5.07.80.23422015-04-10
CVE-2016-66644.77.00.54392016-12-13
CVE-2024-536914.68.80.48052024-12-06
CVE-2024-504044.48.80.44292024-12-06
CVE-2019-1064 KEV4.37.80.12222019-06-12
CVE-2019-10021014.26.40.49272019-04-01
CVE-2019-1315 KEV4.07.80.07602019-10-10
CVE-2025-214204.07.80.41472025-02-11