Skip to main content

CWE archive

CWE-271 CVEs

Programmatic archive

12 CVEs tagged with CWE-2711 Critical, 7 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-44477

Published May 28, 2026

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its Postgr…

CVSS 9.4 · Critical
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-25704

Published Mar 30, 2026

A Privilege Dropping / Lowering Errors/Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in  cosmic-greeter can allow an attacker to regain privileges that should ha…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-53819

Published Jul 14, 2025

Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated privileges (root), instead of the build users. The fix was a…

CVSS 7.9 · High

CVE-2025-23395

Published May 26, 2025

Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path. This allows unprivileged users to create files in arbitrary…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2024-35179

Published May 15, 2024

Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary f…

CVSS 6.8 · Medium

CVE-2024-0985

Published Feb 8, 2024

Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38496

Published Jul 25, 2023

Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22648

Published Jun 1, 2023

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This wou…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3569

Published Oct 17, 2022

Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' u…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1