CWE-270 · 22 records
Privilege Context Switching Error
CVEs in this class
22 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
76This week | CVE-2021-3493Weaponized | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities canonical · ubuntu linux · CWE-270 | High7.8 | KEV | 49.2% | Apr 17, 2021 |
40Plan | CVE-2023-25754No exploit | Apache Airflow: Privilege escalation using airflow logsapache · airflow · CWE-270 | Critical9.8 | — | 2.3% | May 8, 2023 |
35Monitor | CVE-2023-37912No exploit | XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macroxwiki · xwiki-rendering · CWE-270 | High8.8 | — | 1.2% | Oct 25, 2023 |
35Monitor | CVE-2024-8641No exploit | Privilege Context Switching Error in GitLabgitlab · gitlab · CWE-270 | High8.8 | — | 0.5% | Sep 12, 2024 |
35Monitor | CVE-2024-36513No exploit | A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 alfortinet · forticlient · CWE-270 | High8.8 | — | 0.2% | Nov 12, 2024 |
33Monitor | CVE-2024-11263No exploit | arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=yzephyrproject · zephyr · CWE-270 | High8.4 | — | 0.2% | Nov 15, 2024 |
32Monitor | CVE-2025-9408No exploit | Userspace privilege escalation vulnerability on Cortex Mzephyrproject-rtos · zephyr · CWE-270 | High8.1 | — | 0.1% | Nov 11, 2025 |
31Monitor | CVE-2017-2663No exploit | It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and credhat · subscription-manager · CWE-270 | High7.8 | — | 0.4% | Jul 27, 2018 |
31Monitor | CVE-2025-60721No exploit | Windows Administrator Protection Elevation of Privilege Vulnerabilitymicrosoft · windows 11 24h2 · CWE-270 | High7.8 | — | 0.4% | Nov 11, 2025 |
31Monitor | CVE-2024-46975No exploit | GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mappingimagination technologies · graphics ddk · CWE-270 | High7.9 | — | 0.2% | Feb 22, 2025 |
30Monitor | CVE-2026-34853No exploit | Permission bypass vulnerability in the LBS module.huawei · harmonyos · CWE-270 | High7.5 | — | 0.2% | Apr 13, 2026 |
26Monitor | CVE-2020-7019No exploit | In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security.elastic · elasticsearch · CWE-270 | Medium6.5 | — | 1.2% | Aug 18, 2020 |
26Monitor | CVE-2024-12570No exploit | Privilege Context Switching Error in GitLabgitlab · gitlab · CWE-270 | Medium6.7 | — | 0.4% | Dec 12, 2024 |
24Monitor | CVE-2025-26499No exploit | Under heavy system utilization a random race condition can occur during authentication or token refresh operation.wind river studio developer · wind river studio developer · CWE-270 | Medium6.0 | — | 0.1% | Sep 11, 2025 |
22Monitor | CVE-2024-37294No exploit | Aimeos denial of service vulnerability in SaaS and marketplace setupsaimeos · aimeos-core · CWE-270 | Medium5.5 | — | 0.4% | Jun 11, 2024 |
22Monitor | CVE-2024-47173No exploit | Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setupsaimeos · ai-admin-graphql · CWE-270 | Medium5.5 | — | 0.4% | Oct 24, 2024 |
22Monitor | CVE-2025-46406No exploit | A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Dgallagher · command centre server · CWE-270 | Medium5.6 | — | 0.1% | Jul 9, 2025 |
21Monitor | CVE-2020-1719No exploit | A flaw was found in wildfly.redhat · wildfly · CWE-270 | Medium5.4 | — | 0.6% | Jun 7, 2021 |
21Monitor | CVE-2024-51987No exploit | HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnectduendesoftware · duende.accesstokenmanagement · CWE-270 | Medium5.4 | — | 0.2% | Nov 7, 2024 |
20Monitor | CVE-2025-49583No exploit | XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin rightxwiki · xwiki · CWE-270 | Medium5.1 | — | 0.3% | Jun 13, 2025 |
12Monitor | CVE-2020-7020No exploit | Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used.elastic · elasticsearch · CWE-270 | Low3.1 | — | 1.0% | Oct 22, 2020 |
8Monitor | CVE-2025-55210No exploit | FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopessangoma · freepbx · CWE-270 | Low2.0 | — | 0.3% | Feb 12, 2026 |
- CVE-2021-349376This week
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities
HighCVSS 7.8KEVWeaponizedEPSS 49%canonical · ubuntu linuxApr 17, 2021
- CVE-2023-2575440Plan
Apache Airflow: Privilege escalation using airflow logs
CriticalCVSS 9.8No exploitEPSS 2%apache · airflowMay 8, 2023
- CVE-2023-3791235Monitor
XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
HighCVSS 8.8No exploitEPSS 1%xwiki · xwiki-renderingOct 25, 2023
- CVE-2024-864135Monitor
Privilege Context Switching Error in GitLab
HighCVSS 8.8No exploitEPSS 0%gitlab · gitlabSep 12, 2024
- CVE-2024-3651335Monitor
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 al
HighCVSS 8.8No exploitEPSS 0%fortinet · forticlientNov 12, 2024
- CVE-2024-1126333Monitor
arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y
HighCVSS 8.4No exploitEPSS 0%zephyrproject · zephyrNov 15, 2024
- CVE-2025-940832Monitor
Userspace privilege escalation vulnerability on Cortex M
HighCVSS 8.1No exploitEPSS 0%zephyrproject-rtos · zephyrNov 11, 2025
- CVE-2017-266331Monitor
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and c
HighCVSS 7.8No exploitEPSS 0%redhat · subscription-managerJul 27, 2018
- CVE-2025-6072131Monitor
Windows Administrator Protection Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 0%microsoft · windows 11 24h2Nov 11, 2025
- CVE-2024-4697531Monitor
GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mapping
HighCVSS 7.9No exploitEPSS 0%imagination technologies · graphics ddkFeb 22, 2025
- CVE-2026-3485330Monitor
Permission bypass vulnerability in the LBS module.
HighCVSS 7.5No exploitEPSS 0%huawei · harmonyosApr 13, 2026
- CVE-2020-701926Monitor
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security.
MediumCVSS 6.5No exploitEPSS 1%elastic · elasticsearchAug 18, 2020
- CVE-2024-1257026Monitor
Privilege Context Switching Error in GitLab
MediumCVSS 6.7No exploitEPSS 0%gitlab · gitlabDec 12, 2024
- CVE-2025-2649924Monitor
Under heavy system utilization a random race condition can occur during authentication or token refresh operation.
MediumCVSS 6.0No exploitEPSS 0%wind river studio developer · wind river studio developerSep 11, 2025
- CVE-2024-3729422Monitor
Aimeos denial of service vulnerability in SaaS and marketplace setups
MediumCVSS 5.5No exploitEPSS 0%aimeos · aimeos-coreJun 11, 2024
- CVE-2024-4717322Monitor
Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups
MediumCVSS 5.5No exploitEPSS 0%aimeos · ai-admin-graphqlOct 24, 2024
- CVE-2025-4640622Monitor
A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one D
MediumCVSS 5.6No exploitEPSS 0%gallagher · command centre serverJul 9, 2025
- CVE-2020-171921Monitor
A flaw was found in wildfly.
MediumCVSS 5.4No exploitEPSS 1%redhat · wildflyJun 7, 2021
- CVE-2024-5198721Monitor
HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnect
MediumCVSS 5.4No exploitEPSS 0%duendesoftware · duende.accesstokenmanagementNov 7, 2024
- CVE-2025-4958320Monitor
XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
MediumCVSS 5.1No exploitEPSS 0%xwiki · xwikiJun 13, 2025
- CVE-2020-702012Monitor
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used.
LowCVSS 3.1No exploitEPSS 1%elastic · elasticsearchOct 22, 2020
- CVE-2025-552108Monitor
FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
LowCVSS 2.0No exploitEPSS 0%sangoma · freepbxFeb 12, 2026