Skip to main content

CWE archive

CWE-270 CVEs

Programmatic archive

26 CVEs tagged with CWE-2705 Critical, 9 High, 10 Medium, 2 Low, 0 Unrated.

CVE-2026-9560

Published May 26, 2026

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC c…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34853

Published Apr 13, 2026

Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-55210

Published Feb 12, 2026

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege esca…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-9408

Published Nov 11, 2025

System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace processes.

CVSS 8.1 · High

CVE-2025-26499

Published Sep 11, 2025

Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a token intended for ano…

CVSS 6.0 · Medium

CVE-2025-46406

Published Jul 10, 2025

A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged a…

CVSS 5.6 · Medium

CVE-2025-49583

Published Jun 13, 2025

XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49581

Published Jun 13, 2025

XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46975

Published Feb 22, 2025

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.

CVSS 7.9 · High

CVE-2024-12570

Published Dec 12, 2024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11263

Published Nov 15, 2024

When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the li…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-36513

Published Nov 12, 2024

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated u…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-51987

Published Nov 8, 2024

Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` ma…

CVSS 5.4 · Medium

CVE-2024-47173

Published Oct 24, 2024

Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential de…

CVSS 5.5 · Medium

CVE-2024-8641

Published Sep 12, 2024

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37294

Published Jun 11, 2024

Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of serv…

CVSS 5.5 · Medium

CVE-2023-37912

Published Oct 25, 2023

XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-renderi…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25754

Published May 8, 2023

Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26475

Published Mar 2, 2023

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executin…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-1719

Published Jun 7, 2021

A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3493

Published Apr 17, 2021

The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system.…

CVSS 8.8 · High
evidence mentions
7
Buzz score
53.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-7020

Published Oct 22, 2020

Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security p…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-7019

Published Aug 18, 2020

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more pr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2