CWE-367

Medium likelihood

Time-of-check Time-of-use (TOCTOU) Race Condition

Parent: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

589 vulnerabilities with CWE-367
CVE-2025-34027 CRITICAL
Versa Concerto - Auth Bypass & RCE
CVE-2025-47290 MEDIUM
Linuxfoundation Containerd < 2.1.1 - TOCTOU Race Condition
CVSS 5.9
CVE-2025-30663 HIGH
Zoom Meeting Software Development Kit < 6.4.0 - TOCTOU Race Condition
CVSS 8.8
CVE-2025-20082 HIGH
Intel(R) Server D50DNP/M50FCP - Privilege Escalation
CVSS 7.5
CVE-2025-29969 HIGH
Windows Fundamentals - Code Injection
CVSS 7.5
CVE-2025-29833 HIGH
Windows Virtual Machine Bus - Code Injection
CVSS 7.7
CVE-2025-46336 MEDIUM
Rack::Session <2.1.1 - Privilege Escalation
CVSS 4.2
CVE-2025-30101 MEDIUM
Dell PowerScale OneFS <9.10.1.0 - DoS
CVSS 4.4
CVE-2025-32441 MEDIUM
Rack < 2.2.14 - Race Condition
CVSS 4.2
CVE-2025-3599 MEDIUM
Broadcom Symantec Eraser Engine < 119.1.7.8 - TOCTOU Race Condition
CVSS 6.5
CVE-2025-46328 LOW
Snowflake-Connector-NodeJS <2.0.4 - Privilege Escalation
CVSS 3.3
CVE-2025-46327 LOW
gosnowflake <1.13.3 - Info Disclosure
CVSS 3.3
CVE-2025-46326 LOW
Snowflake Connector <4.4.1 - Info Disclosure
CVSS 3.3
CVE-2025-22060 MEDIUM
Linux kernel - Memory Corruption
CVSS 4.7
CVE-2025-32784 HIGH
conda-forge-webservices <2025.4.10 - TOCTOU
CVE-2025-27812 HIGH
MSI Center <2.0.52.0 - Privilege Escalation
CVSS 8.1
CVE-2025-21191 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20978 - TOCTOU Race Condition
CVSS 7.0
CVE-2025-21431 MEDIUM
Qualcomm Qam8255p Firmware - TOCTOU Race Condition
CVSS 5.5
CVE-2025-21998 MEDIUM
Linux kernel - Use After Free
CVSS 4.7
CVE-2025-21958 MEDIUM
Linux kernel - Info Disclosure
CVSS 4.7
CVE-2025-22224 CRITICAL KEV
VMware ESXi, Workstation - Code Injection
CVSS 9.3
CVE-2025-0759 LOW
IBM EntireX 11.1 - Info Disclosure
CVSS 3.3
CVE-2025-21746 MEDIUM
Linux kernel - Buffer Overflow
CVSS 4.7
CVE-2025-26620 MEDIUM
Nuget Duende.accesstokenmanagement < 3.2.0 - TOCTOU Race Condition
CVE-2025-23359 HIGH
Nvidia Container Toolkit < 1.17.4 - TOCTOU Race Condition
CVSS 8.3
Details
Vulnerabilities 589
Exploit Likelihood Medium