Skip to content
Noroxi

CWE-270 · 22 records

Privilege Context Switching Error

CVEs in this class

22 records

  • CVE-2021-3493
    76This week

    The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities

    HighCVSS 7.8KEVWeaponizedEPSS 49%

    canonical · ubuntu linuxApr 17, 2021

  • Apache Airflow: Privilege escalation using airflow logs

    CriticalCVSS 9.8No exploitEPSS 2%

    apache · airflowMay 8, 2023

  • XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro

    HighCVSS 8.8No exploitEPSS 1%

    xwiki · xwiki-renderingOct 25, 2023

  • CVE-2024-8641
    35Monitor

    Privilege Context Switching Error in GitLab

    HighCVSS 8.8No exploitEPSS 0%

    gitlab · gitlabSep 12, 2024

  • A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 al

    HighCVSS 8.8No exploitEPSS 0%

    fortinet · forticlientNov 12, 2024

  • arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y

    HighCVSS 8.4No exploitEPSS 0%

    zephyrproject · zephyrNov 15, 2024

  • CVE-2025-9408
    32Monitor

    Userspace privilege escalation vulnerability on Cortex M

    HighCVSS 8.1No exploitEPSS 0%

    zephyrproject-rtos · zephyrNov 11, 2025

  • CVE-2017-2663
    31Monitor

    It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and c

    HighCVSS 7.8No exploitEPSS 0%

    redhat · subscription-managerJul 27, 2018

  • Windows Administrator Protection Elevation of Privilege Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    microsoft · windows 11 24h2Nov 11, 2025

  • GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mapping

    HighCVSS 7.9No exploitEPSS 0%

    imagination technologies · graphics ddkFeb 22, 2025

  • Permission bypass vulnerability in the LBS module.

    HighCVSS 7.5No exploitEPSS 0%

    huawei · harmonyosApr 13, 2026

  • CVE-2020-7019
    26Monitor

    In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security.

    MediumCVSS 6.5No exploitEPSS 1%

    elastic · elasticsearchAug 18, 2020

  • Privilege Context Switching Error in GitLab

    MediumCVSS 6.7No exploitEPSS 0%

    gitlab · gitlabDec 12, 2024

  • Under heavy system utilization a random race condition can occur during authentication or token refresh operation.

    MediumCVSS 6.0No exploitEPSS 0%

    wind river studio developer · wind river studio developerSep 11, 2025

  • Aimeos denial of service vulnerability in SaaS and marketplace setups

    MediumCVSS 5.5No exploitEPSS 0%

    aimeos · aimeos-coreJun 11, 2024

  • Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups

    MediumCVSS 5.5No exploitEPSS 0%

    aimeos · ai-admin-graphqlOct 24, 2024

  • A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one D

    MediumCVSS 5.6No exploitEPSS 0%

    gallagher · command centre serverJul 9, 2025

  • CVE-2020-1719
    21Monitor

    A flaw was found in wildfly.

    MediumCVSS 5.4No exploitEPSS 1%

    redhat · wildflyJun 7, 2021

  • HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnect

    MediumCVSS 5.4No exploitEPSS 0%

    duendesoftware · duende.accesstokenmanagementNov 7, 2024

  • XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right

    MediumCVSS 5.1No exploitEPSS 0%

    xwiki · xwikiJun 13, 2025

  • CVE-2020-7020
    12Monitor

    Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used.

    LowCVSS 3.1No exploitEPSS 1%

    elastic · elasticsearchOct 22, 2020

  • FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes

    LowCVSS 2.0No exploitEPSS 0%

    sangoma · freepbxFeb 12, 2026

All vulnerability classes