CWE-367
Medium likelihoodTime-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
703 vulnerabilities with CWE-367
CVE-2026-58198
MEDIUM
ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
CVSS 5.5
CVE-2026-54777
MEDIUM
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CVSS 6.5
CVE-2026-43927
MEDIUM
FOSSBilling has race condition in cart checkout that bypasses promo code usage limits
CVE-2026-25271
HIGH
Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service
CVSS 7.8
CVE-2026-58299
HIGH
Microsoft Edge for Android Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-55950
MEDIUM
DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions
CVSS 5.9
CVE-2026-24260
HIGH
Nvidia Container Toolkit - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS 8.5
CVE-2026-12374
MEDIUM
Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool
CVE-2026-14160
MEDIUM
Samsung Open Source Escargot - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS 5.9
CVE-2026-57959
MEDIUM
Hi.Events 1.9.0 - Promo Code Max-Usage Bypass via Asynchronous Job Race Condition
CVSS 5.9
CVE-2026-13742
MEDIUM
Lack of signature verification before execution of downloaded content
CVE-2026-54370
MEDIUM
acl < 2.4.0 TOCTOU Symlink Traversal via getfacl/setfacl/chacl
CVSS 6.3
CVE-2026-13502
MEDIUM
antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou
CVSS 4.5
CVE-2026-54353
HIGH
Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation
CVSS 8.5
CVE-2026-52885
MEDIUM
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
CVSS 6.3
CVE-2026-53250
HIGH
xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
CVSS 7.8
CVE-2026-53145
HIGH
drm/gem: Try to fix change_handle ioctl, attempt 4
CVSS 7.8
CVE-2026-53945
MEDIUM
Ghost: Server-side request forgery via DNS rebinding in external request handling
CVSS 4.0
CVE-2026-52991
HIGH
sched/psi: fix race between file release and pressure write
CVSS 7.8
CVE-2026-54327
LOW
Pi 0.74.0 to < 0.78.1 - auth.json Credential Exposure Race Condition
CVSS 2.2
CVE-2026-48931
LOW
Node - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS 3.7
CVE-2026-41045
HIGH
Weak polkit authentication check in qSnapper
CVSS 8.1
CVE-2026-48983
MEDIUM
pam_usb < 0.9.2 - Symlink Race in Pad Directory Creation
CVSS 5.8
CVE-2026-6733
LOW
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVSS 3.7
CVE-2026-54228
HIGH
Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories
CVSS 7.8
Details
Vulnerabilities
703
Exploit Likelihood
Medium