CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

649 vulnerabilities with CWE-367
CVE-2026-1035 LOW
Keycloak - Refresh Token Reuse Bypass via Non-Atomic Validation in TokenManager
CVSS 3.1
CVE-2026-23950 HIGH
node-tar <= 7.5.3 - Arbitrary File Overwrite via Unicode Path Collision Race Condition
CVSS 8.8
CVE-2026-21912 MEDIUM
Junos OS on MX10k Series - Authenticated Denial of Service via 'show system firmware' CLI Command
CVSS 5.5
CVE-2026-22820 LOW
outray < 0.1.5 - Time-of-check Time-of-use Race Condition
CVSS 3.7
CVE-2026-20831 HIGH
Windows Ancillary Function Driver - Privilege Escalation
CVSS 7.8
CVE-2026-20816 HIGH
Windows Installer - Privilege Escalation
CVSS 7.8
CVE-2026-20809 HIGH
Windows Kernel Memory - Privilege Escalation
CVSS 7.8
CVE-2026-22701 MEDIUM
filelock < 3.20.3 - TOCTOU Race Condition in SoftFileLock _acquire Method
CVSS 5.3
CVE-2025-41259 HIGH
SWUpdate Untrusted Script Execution via Signed Update TOCTOU
CVE-2025-64390 HIGH
Sony PS4 < 13.02 - Privilege Escalation
CVSS 7.4
CVE-2025-59610 MEDIUM
Time-of-check Time-of-use (TOCTOU) Race Condition in Camera Driver
CVSS 6.4
CVE-2025-71216 HIGH
Trend Micro, Inc. TrendAI Apex One (Mac) - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS 7.8
CVE-2025-71215 HIGH
Trend Micro, Inc. TrendAI Apex One (Mac) - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSS 7.0
CVE-2025-52532 LOW
AMD Radeon PRO V620 - Denial of Service via MxGPU-Virtualization Driver Race Condition
CVE-2025-69233 MEDIUM
Apache CloudStack: Domain/account resources limits not honored
CVSS 6.5
CVE-2025-47407 HIGH
Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service
CVSS 7.8
CVE-2025-22850 MEDIUM
Intel UEFI PdaSmm - Info Disclosure
CVE-2025-20028 HIGH
Intel WheaERST SMM - Privilege Escalation
CVE-2025-71225 MEDIUM
Linux Kernel - Privilege Escalation
CVSS 5.3
CVE-2025-13818 MEDIUM
ESET Management Agent - Privilege Escalation
CVSS 6.7
CVE-2025-67124 MEDIUM
miniserve < 0.32.0 - Arbitrary File Overwrite via Symlink Race in Upload Finalization
CVSS 6.8
CVE-2025-71111 MEDIUM
Linux Kernel - Time-of-check Time-of-use Race Condition in w83791d FAN_FROM_REG Macro
CVSS 4.7
CVE-2025-47344 MEDIUM
Qualcomm Firmware - Memory Corruption via Sensor Utility Operations
CVSS 6.7
CVE-2025-47332 MEDIUM
Qualcomm FastConnect and QCM/QCS/SM/SG Firmware - Memory Corruption via Config Call Processing
CVSS 6.7
CVE-2025-53594 MEDIUM
Qfinder Pro Mac <7.13.0 - Path Traversal
Details
Vulnerabilities 649
Exploit Likelihood Medium