CWE-270
27 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-270page 1 of 1
- CVE-2017-2663HIGHCVSS 8.2EG 7.82018-07-27
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local attacker could use these methods to gain …
- CVE-2019-14819HIGHCVSS 8.8EG 8.82020-01-07
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivil…
- CVE-2020-1719MEDIUMCVSS 5.4EG 5.42021-06-07
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wil…
- CVE-2020-25696HIGHCVSS 7.5EG 7.52020-11-23
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server…
- CVE-2020-7019MEDIUMCVSS 6.5EG 6.52020-08-18
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs the same query another more privileged user recently ran, the scrolling search can leak fi…
- CVE-2020-7020LOWCVSS 3.1EG 3.12020-10-22
Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This coul…
- CVE-2021-3493HIGHCVSS 8.8EG 9.0⚠ KEV2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along…
- CVE-2023-25754CRITICALCVSS 9.8EG 9.82023-05-08
Privilege Context Switching Error vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.6.0.
- CVE-2023-26475CRITICALCVSS 9.9EG 9.92023-03-02
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by a…
- CVE-2023-37912CRITICALCVSS 9.9EG 9.92023-10-25
XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-…
- CVE-2024-11263CRITICALCVSS 9.3EG 9.32024-11-15
When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which is then used by the linker to relax accesses to global symbols.
- CVE-2024-12570MEDIUMCVSS 6.7EG 6.72024-12-12
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to o…
- CVE-2024-36513HIGHCVSS 8.2EG 8.22024-11-12
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
- CVE-2024-37294MEDIUMCVSS 5.5EG 5.52024-06-11
Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 202…
- CVE-2024-46975HIGHCVSS 7.9EG 7.92025-02-22
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.
- CVE-2024-47173MEDIUMCVSS 5.5EG 5.52024-10-24
Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.
- CVE-2024-51987MEDIUMCVSS 5.4EG 5.42024-11-08
Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's access token after a token refresh …
- CVE-2024-8641MEDIUMCVSS 6.7EG 6.72024-09-12
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obt…
- CVE-2025-26499MEDIUMCVSS 6.0EG 6.02025-09-11
Under heavy system utilization a random race condition can occur during authentication or token refresh operation. This flaw allows one user to be granted a token intended for another user, resulting in impersonation until the session is e…
- CVE-2025-46406MEDIUMCVSS 5.6EG 5.62025-07-10
A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects …
- CVE-2025-49581HIGHCVSS 8.8EG 8.82025-06-13
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki inst…
- CVE-2025-49583LOWCVSS 3.5EG 3.52025-06-13
XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this o…
- CVE-2025-55210HIGHCVSS 7.5EG 7.52026-02-12
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to 17.0.5 and 16.0.17, FreePBX module api (PBX API) is vulnerable to privilege escalation by authenticated users with REST/GraphQL API access. …
- CVE-2025-60721HIGHCVSS 7.8EG 7.82025-11-11
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
- CVE-2025-9408HIGHCVSS 8.1EG 8.12025-11-11
System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege escalation for malicious userspace processes.
- CVE-2026-34853HIGHCVSS 7.7EG 7.72026-04-13
Permission bypass vulnerability in the LBS module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-9560HIGHCVSS 7.8EG 7.82026-05-26
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
Map vulnerabilities like CWE-270 to your infrastructure
EchelonGraph correlates every CVE — across CWE-270 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →