Skip to main content

CWE archive

CWE-273 CVEs

Programmatic archive

39 CVEs tagged with CWE-2738 Critical, 20 High, 8 Medium, 3 Low, 0 Unrated.

CVE-2026-60085

Published Jul 15, 2026

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocked_paths, blocked_imports, allo…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-0099

Published Jun 1, 2026

In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalat…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44073

Published May 21, 2026

Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a remote authenticated attacker to retain elevated privileges u…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-32107

Published Apr 17, 2026

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper pr…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-21882

Published Mar 2, 2026

theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privileg…

CVSS 8.4 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-62175

Published Oct 13, 2025

Mastodon is a free, open-source social network server based on ActivityPub. In versions before 4.4.6, 4.3.14, and 4.2.27, disabling or suspending a user account does not disconnec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1003

Published Feb 4, 2025

A potential vulnerability has been identified in HP Anyware Agent for Linux which might allow for authentication bypass which may result in escalation of privilege. HP is releasin…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-0657

Published Nov 17, 2024

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange…

CVSS 3.4 · Low

CVE-2024-8382

Published Sep 3, 2024

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21848

Published Apr 5, 2024

Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if the…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-25420

Published Mar 26, 2024

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-47129

Published Mar 15, 2024

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: skip expectations for confirmed conntrack nft_ct_expect_obj_eval() calls nf_ct_ext_add() f…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52433

Published Feb 20, 2024

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this transaction…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34322

Published Jan 5, 2024

For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen itself needs to be mapped when PV guests run,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5369

Published Oct 4, 2023

Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offse…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35692

Published Jul 14, 2023

In getLocationCache of GeoLocation.java, there is a possible way to send a mock location during an emergency call due to improper input validation. This could lead to local escala…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21246

Published Jul 13, 2023

In ShortcutInfo of ShortcutInfo.java, there is a possible way for an app to retain notification listening access due to an uncaught exception. This could lead to local escalation…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-0358

Published Aug 29, 2022

A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files i…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37839

Published Jul 6, 2022

Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3982

Published Apr 29, 2022

Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way C…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36372

Published Nov 19, 2021

In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2