CWE-367
Medium likelihoodTime-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
703 vulnerabilities with CWE-367
CVE-2026-67433
MEDIUM
Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration
CVE-2026-13113
MEDIUM
Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
CVSS 6.5
CVE-2026-56822
HIGH
Netty: TOCTOU in OcspServerCertificateValidator
CVSS 7.4
CVE-2026-55391
HIGH
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
CVSS 7.5
CVE-2026-62428
HIGH
grant-table: type confusion in grant-copy
CVSS 7.8
CVE-2026-59676
MEDIUM
Local File Deletion Attack Vector in rm_rf() in seunshare
CVE-2026-65598
HIGH
n8n before 1.123.64 Remote Code Execution via Git Clone
CVSS 7.5
CVE-2026-16082
MEDIUM
Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
CVSS 5.3
CVE-2026-54242
MEDIUM
Statamic: Server-Side Request Forgery via Glide (DNS rebinding)
CVSS 4.9
CVE-2026-62212
HIGH
OpenClaw < 2026.5.28 Authentication Bypass via safeFetch
CVSS 7.1
CVE-2026-53410
HIGH
Zoom Clients for Windows - Race Condition
CVSS 7.0
CVE-2026-15449
MEDIUM
TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption
CVE-2026-53518
HIGH
Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption
CVSS 8.1
CVE-2026-53517
HIGH
Better Auth OAuth Provider < 1.6.11 - Refresh Token Replay Race Condition
CVSS 8.1
CVE-2026-45804
HIGH
Diffusers: TOCTOU Trust Remote Code Bypass
CVSS 7.5
CVE-2026-48344
HIGH
GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
CVSS 7.8
CVE-2026-57973
MEDIUM
Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
CVSS 6.3
CVE-2026-56648
HIGH
Microsoft Windows 10 Version 1607 - Windows NFS Server Elevation of Privilege Vulnerability
CVSS 7.5
CVE-2026-56178
MEDIUM
Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
CVSS 5.5
CVE-2026-50673
HIGH
Microsoft Windows 10 Version 1607 - Windows Kernel Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50658
HIGH
Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-4018
MEDIUM
TOCTOU race condition in the QNX Neutrino kernel impacts versions of the QNX Software Development Platform and QNX OS for Safety
CVSS 6.4
CVE-2026-62189
HIGH
OpenClaw < 2026.6.9 Symlink Following via Mirror Sync
CVSS 7.1
CVE-2026-45203
HIGH
GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU
CVSS 7.8
CVE-2026-56676
HIGH
9router: Image prefetch DNS rebinding allows SSRF to internal services
CVSS 7.4
Details
Vulnerabilities
703
Exploit Likelihood
Medium