CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

589 vulnerabilities with CWE-367
CVE-2026-1035 LOW
Org.keycloak Keycloak-services - TOCTOU Race Condition
CVSS 3.1
CVE-2026-23950 HIGH
node-tar <7.5.3 - Code Injection
CVSS 8.8
CVE-2026-21912 MEDIUM
Junos OS - TOCTOU
CVSS 5.5
CVE-2026-22820 LOW
Outray < 0.1.5 - TOCTOU Race Condition
CVSS 3.7
CVE-2026-20831 HIGH
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
CVE-2026-20816 HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2026-20809 HIGH
Windows Kernel Memory - Privilege Escalation
CVSS 7.8
CVE-2026-22701 MEDIUM
Pypi Filelock < 3.20.3 - Race Condition
CVSS 5.3
CVE-2025-22850 MEDIUM
Intel UEFI PdaSmm - Info Disclosure
CVE-2025-20028 HIGH
Intel WheaERST SMM - Privilege Escalation
CVE-2025-71225 MEDIUM
Linux Kernel - Privilege Escalation
CVSS 5.3
CVE-2025-13818 MEDIUM
ESET Management Agent - Privilege Escalation
CVSS 6.7
CVE-2025-67124 MEDIUM
Svenstaro Miniserve < 0.32.0 - Symlink Following
CVSS 6.8
CVE-2025-71111 MEDIUM
Linux kernel - TOCTOU
CVSS 4.7
CVE-2025-47344 MEDIUM
Qualcomm Qcm5430 Firmware - TOCTOU Race Condition
CVSS 6.7
CVE-2025-47332 MEDIUM
Qualcomm Fastconnect 6200 Firmware - TOCTOU Race Condition
CVSS 6.7
CVE-2025-53594 MEDIUM
Qfinder Pro Mac <7.13.0 - Path Traversal
CVE-2025-61037 HIGH
SevenCs ORCA G2 2.0.1.35 - Privilege Escalation
CVSS 7.0
CVE-2025-69211 HIGH
Nestjs Platform-fastify < 11.1.11 - TOCTOU Race Condition
CVSS 7.4
CVE-2025-64645 HIGH
IBM Concert < 2.2.0 - TOCTOU Race Condition
CVSS 7.7
CVE-2025-34290 HIGH
Versa SASE Client for Windows <7.9.4 - Privilege Escalation
CVE-2025-62004 HIGH
Bullwall Server Intrusion Protection - TOCTOU Race Condition
CVSS 7.5
CVE-2025-62003 HIGH
Bullwall Server Intrusion Protection - TOCTOU Race Condition
CVSS 7.5
CVE-2025-68146 MEDIUM
Pypi Filelock < 3.20.1 - Race Condition
CVSS 6.3
CVE-2025-62724 MEDIUM
Open OnDemand <4.0.8, <3.1.16 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 589
Exploit Likelihood Medium