CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

530 vulnerabilities with CWE-367
CVE-2026-26017 HIGH
CoreDNS <1.14.2 - Auth Bypass
CVSS 7.7
CVE-2026-27750 HIGH
Avira Internet Security - Privilege Escalation
CVSS 7.8
CVE-2026-20445 MEDIUM
MDDP - DoS
CVSS 4.4
CVE-2026-20438 MEDIUM
MAE - Privilege Escalation
CVSS 6.4
CVE-2026-21725 LOW
Grafana - Privilege Escalation
CVSS 2.6
CVE-2026-27128 MEDIUM
Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - Auth Bypass
CVSS 4.8
CVE-2026-27127 MEDIUM
Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - SSRF
CVSS 6.3
CVE-2026-27189 MEDIUM
OpenSift <=1.1.2-alpha - Memory Corruption
CVSS 6.6
CVE-2026-25738 MEDIUM
Indico <3.3.10 - SSRF
CVSS 4.3
CVE-2026-20796 LOW
Mattermost <10.11.9 - Info Disclosure
CVSS 3.1
CVE-2026-26224
Intego Log Reporter - Privilege Escalation
CVE-2026-20677 CRITICAL
macOS Tahoe <26.3 - Info Disclosure
CVSS 9.0
CVE-2023-31324 HIGH
AMD Secure Processor - TOCTOU
CVSS 7.8
CVE-2023-20548 HIGH
AMD Secure Processor - Memory Corruption
CVSS 7.8
CVE-2024-36311
SMM - Memory Corruption
CVE-2026-25728 HIGH
ClipBucket <5.5.3 - Code Injection
CVSS 7.5
CVE-2026-21523 HIGH
Microsoft Visual Studio Code < 1.109.2 - TOCTOU Race Condition
CVSS 8.0
CVE-2026-21240 HIGH
Windows HTTP.sys - Privilege Escalation
CVSS 7.8
CVE-2026-25641 CRITICAL
Nyariv Sandboxjs < 0.8.29 - TOCTOU Race Condition
CVSS 10.0
CVE-2025-13818 MEDIUM
ESET Management Agent - Privilege Escalation
CVSS 6.7
CVE-2026-25052 CRITICAL
N8n < 1.123.18 - TOCTOU Race Condition
CVSS 9.9
CVE-2026-24071 HIGH
Native Access - Info Disclosure
CVSS 7.8
CVE-2025-67124 MEDIUM
Svenstaro Miniserve < 0.32.0 - Symlink Following
CVSS 6.8
CVE-2026-23988 HIGH
Rufus <4.11 - Code Injection
CVSS 7.3
CVE-2026-22281 LOW
Dell Powerscale Onefs < 9.5.1.6 - TOCTOU Race Condition
CVSS 3.5
Details
Vulnerabilities 530
Exploit Likelihood Medium