CWE-270 · 22 записей
Privilege Context Switching Error
CVE этого класса
22 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
76На этой неделе | CVE-2021-3493Готовый эксплойт | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities canonical · ubuntu linux · CWE-270 | Высокая7,8 | KEV | 49,2 % | 17 апр. 2021 г. |
40В плане | CVE-2023-25754Эксплойта нет | Apache Airflow: Privilege escalation using airflow logsapache · airflow · CWE-270 | Критическая9,8 | — | 2,3 % | 8 мая 2023 г. |
35Наблюдать | CVE-2023-37912Эксплойта нет | XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macroxwiki · xwiki-rendering · CWE-270 | Высокая8,8 | — | 1,2 % | 25 окт. 2023 г. |
35Наблюдать | CVE-2024-8641Эксплойта нет | Privilege Context Switching Error in GitLabgitlab · gitlab · CWE-270 | Высокая8,8 | — | 0,5 % | 12 сент. 2024 г. |
35Наблюдать | CVE-2024-36513Эксплойта нет | A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 alfortinet · forticlient · CWE-270 | Высокая8,8 | — | 0,2 % | 12 нояб. 2024 г. |
33Наблюдать | CVE-2024-11263Эксплойта нет | arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=yzephyrproject · zephyr · CWE-270 | Высокая8,4 | — | 0,2 % | 15 нояб. 2024 г. |
32Наблюдать | CVE-2025-9408Эксплойта нет | Userspace privilege escalation vulnerability on Cortex Mzephyrproject-rtos · zephyr · CWE-270 | Высокая8,1 | — | 0,1 % | 11 нояб. 2025 г. |
31Наблюдать | CVE-2017-2663Эксплойта нет | It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and credhat · subscription-manager · CWE-270 | Высокая7,8 | — | 0,4 % | 27 июл. 2018 г. |
31Наблюдать | CVE-2025-60721Эксплойта нет | Windows Administrator Protection Elevation of Privilege Vulnerabilitymicrosoft · windows 11 24h2 · CWE-270 | Высокая7,8 | — | 0,4 % | 11 нояб. 2025 г. |
31Наблюдать | CVE-2024-46975Эксплойта нет | GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mappingimagination technologies · graphics ddk · CWE-270 | Высокая7,9 | — | 0,2 % | 22 февр. 2025 г. |
30Наблюдать | CVE-2026-34853Эксплойта нет | Permission bypass vulnerability in the LBS module.huawei · harmonyos · CWE-270 | Высокая7,5 | — | 0,2 % | 13 апр. 2026 г. |
26Наблюдать | CVE-2020-7019Эксплойта нет | In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security.elastic · elasticsearch · CWE-270 | Средняя6,5 | — | 1,2 % | 18 авг. 2020 г. |
26Наблюдать | CVE-2024-12570Эксплойта нет | Privilege Context Switching Error in GitLabgitlab · gitlab · CWE-270 | Средняя6,7 | — | 0,4 % | 12 дек. 2024 г. |
24Наблюдать | CVE-2025-26499Эксплойта нет | Under heavy system utilization a random race condition can occur during authentication or token refresh operation.wind river studio developer · wind river studio developer · CWE-270 | Средняя6,0 | — | 0,1 % | 11 сент. 2025 г. |
22Наблюдать | CVE-2024-37294Эксплойта нет | Aimeos denial of service vulnerability in SaaS and marketplace setupsaimeos · aimeos-core · CWE-270 | Средняя5,5 | — | 0,4 % | 11 июн. 2024 г. |
22Наблюдать | CVE-2024-47173Эксплойта нет | Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setupsaimeos · ai-admin-graphql · CWE-270 | Средняя5,5 | — | 0,4 % | 24 окт. 2024 г. |
22Наблюдать | CVE-2025-46406Эксплойта нет | A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Dgallagher · command centre server · CWE-270 | Средняя5,6 | — | 0,1 % | 9 июл. 2025 г. |
21Наблюдать | CVE-2020-1719Эксплойта нет | A flaw was found in wildfly.redhat · wildfly · CWE-270 | Средняя5,4 | — | 0,6 % | 7 июн. 2021 г. |
21Наблюдать | CVE-2024-51987Эксплойта нет | HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnectduendesoftware · duende.accesstokenmanagement · CWE-270 | Средняя5,4 | — | 0,2 % | 7 нояб. 2024 г. |
20Наблюдать | CVE-2025-49583Эксплойта нет | XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin rightxwiki · xwiki · CWE-270 | Средняя5,1 | — | 0,3 % | 13 июн. 2025 г. |
12Наблюдать | CVE-2020-7020Эксплойта нет | Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used.elastic · elasticsearch · CWE-270 | Низкая3,1 | — | 1,0 % | 22 окт. 2020 г. |
8Наблюдать | CVE-2025-55210Эксплойта нет | FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopessangoma · freepbx · CWE-270 | Низкая2,0 | — | 0,3 % | 12 февр. 2026 г. |
- CVE-2021-349376На этой неделе
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 49 %canonical · ubuntu linux17 апр. 2021 г.
- CVE-2023-2575440В плане
Apache Airflow: Privilege escalation using airflow logs
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %apache · airflow8 мая 2023 г.
- CVE-2023-3791235Наблюдать
XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %xwiki · xwiki-rendering25 окт. 2023 г.
- CVE-2024-864135Наблюдать
Privilege Context Switching Error in GitLab
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %gitlab · gitlab12 сент. 2024 г.
- CVE-2024-3651335Наблюдать
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 al
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %fortinet · forticlient12 нояб. 2024 г.
- CVE-2024-1126333Наблюдать
arch: riscv: userspace: potential security risk when CONFIG_RISCV_GP=y
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %zephyrproject · zephyr15 нояб. 2024 г.
- CVE-2025-940832Наблюдать
Userspace privilege escalation vulnerability on Cortex M
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %zephyrproject-rtos · zephyr11 нояб. 2025 г.
- CVE-2017-266331Наблюдать
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and c
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %redhat · subscription-manager27 июл. 2018 г.
- CVE-2025-6072131Наблюдать
Windows Administrator Protection Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %microsoft · windows 11 24h211 нояб. 2025 г.
- CVE-2024-4697531Наблюдать
GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mapping
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %imagination technologies · graphics ddk22 февр. 2025 г.
- CVE-2026-3485330Наблюдать
Permission bypass vulnerability in the LBS module.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · harmonyos13 апр. 2026 г.
- CVE-2020-701926Наблюдать
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %elastic · elasticsearch18 авг. 2020 г.
- CVE-2024-1257026Наблюдать
Privilege Context Switching Error in GitLab
СредняяCVSS 6,7Эксплойта нетEPSS 0 %gitlab · gitlab12 дек. 2024 г.
- CVE-2025-2649924Наблюдать
Under heavy system utilization a random race condition can occur during authentication or token refresh operation.
СредняяCVSS 6,0Эксплойта нетEPSS 0 %wind river studio developer · wind river studio developer11 сент. 2025 г.
- CVE-2024-3729422Наблюдать
Aimeos denial of service vulnerability in SaaS and marketplace setups
СредняяCVSS 5,5Эксплойта нетEPSS 0 %aimeos · aimeos-core11 июн. 2024 г.
- CVE-2024-4717322Наблюдать
Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups
СредняяCVSS 5,5Эксплойта нетEPSS 0 %aimeos · ai-admin-graphql24 окт. 2024 г.
- CVE-2025-4640622Наблюдать
A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one D
СредняяCVSS 5,6Эксплойта нетEPSS 0 %gallagher · command centre server9 июл. 2025 г.
- CVE-2020-171921Наблюдать
A flaw was found in wildfly.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %redhat · wildfly7 июн. 2021 г.
- CVE-2024-5198721Наблюдать
HTTP Client uses incorrect token after refresh in Duende.AccessTokenManagement.OpenIdConnect
СредняяCVSS 5,4Эксплойта нетEPSS 0 %duendesoftware · duende.accesstokenmanagement7 нояб. 2024 г.
- CVE-2025-4958320Наблюдать
XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
СредняяCVSS 5,1Эксплойта нетEPSS 0 %xwiki · xwiki13 июн. 2025 г.
- CVE-2020-702012Наблюдать
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used.
НизкаяCVSS 3,1Эксплойта нетEPSS 1 %elastic · elasticsearch22 окт. 2020 г.
- CVE-2025-552108Наблюдать
FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
НизкаяCVSS 2,0Эксплойта нетEPSS 0 %sangoma · freepbx12 февр. 2026 г.