CWE-367
Medium likelihoodTime-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
704 vulnerabilities with CWE-367
CVE-2025-67124
MEDIUM
miniserve < 0.32.0 - Arbitrary File Overwrite via Symlink Race in Upload Finalization
CVSS 6.8
CVE-2025-71111
MEDIUM
Linux Kernel - Time-of-check Time-of-use Race Condition in w83791d FAN_FROM_REG Macro
CVSS 4.7
CVE-2025-47344
MEDIUM
Qualcomm Firmware - Memory Corruption via Sensor Utility Operations
CVSS 6.7
CVE-2025-47332
MEDIUM
Qualcomm FastConnect and QCM/QCS/SM/SG Firmware - Memory Corruption via Config Call Processing
CVSS 6.7
CVE-2025-53594
MEDIUM
Qfinder Pro Mac <7.13.0 - Path Traversal
CVE-2025-61037
HIGH
SevenCs ORCA G2 2.0.1.35 - Privilege Escalation
CVSS 7.0
CVE-2025-69211
HIGH
NestJS platform-fastify < 11.1.11 - Unauthenticated Middleware Bypass via Fastify URL Encoding
CVSS 7.4
CVE-2025-64645
HIGH
IBM Concert 1.0.0-2.1.0 - Privilege Escalation via Symbolic Link Race Condition
CVSS 7.7
CVE-2025-34290
HIGH
Versa SASE Client for Windows <7.9.4 - Privilege Escalation
CVE-2025-62004
HIGH
BullWall Server Intrusion Protection 4.6.0.0 4.6.0.6 4.6.0.7 4.6.1.4 - Authenticated MFA Bypass via Race Condition
CVSS 7.5
CVE-2025-62003
HIGH
BullWall Server Intrusion Protection 4.6.0.0 4.6.0.6 4.6.0.7 4.6.1.4 - Authenticated MFA Bypass via RDP Connection Delay
CVSS 7.5
CVE-2025-68146
MEDIUM
filelock < 3.20.1 - Time-of-Check-Time-of-Use Race Condition via Symlink Attack
CVSS 6.3
CVE-2025-62724
MEDIUM
Open OnDemand <4.0.8, <3.1.16 - Info Disclosure
CVSS 4.3
CVE-2025-58407
HIGH
Kernel or driver - Memory Corruption
CVSS 7.4
CVE-2025-31146
MEDIUM
Intel Ethernet Adapter Complete Driver Pack <1.5.1.0 - DoS
CVSS 6.1
CVE-2025-27725
MEDIUM
ACAT < 3.13 - Authenticated Denial of Service via Time-of-check Time-of-use Race Condition
CVSS 4.4
CVE-2025-13032
CRITICAL
Avast Antivirus < 25.3 - Local Privilege Escalation via Sandbox Kernel Driver Double Fetch
CVSS 9.9
CVE-2025-64457
MEDIUM
JetBrains dotTrace ReSharper and Rider < 2025.2.5 - Local Privilege Escalation via Race Condition
CVSS 4.2
CVE-2025-64180
CRITICAL
Manager-io/Manager <25.11.1.3085 - Privilege Escalation
CVSS 10.0
CVE-2025-20740
MEDIUM
MediaTek Software Development Kit < 3.7 - Local Information Disclosure via Race Condition in WLAN STA Driver
CVSS 4.7
CVE-2025-64118
MEDIUM
tar 7.5.1 - Information Exposure via Uninitialized Memory in .list with sync: true
CVE-2025-62511
MEDIUM
YtGrabber-TUI < 1.0.1 - Time-of-Check Time-of-Use Race Condition in Config File Creation
CVSS 6.3
CVE-2025-54271
MEDIUM
Adobe Creative Cloud < 6.8.0.821 - Time-of-check Time-of-use Race Condition
CVSS 5.6
CVE-2025-59497
HIGH
Microsoft Defender for Endpoint < 101.25032.0010 - Authenticated Denial of Service via TOCTOU Race Condition
CVSS 7.0
CVE-2025-59261
HIGH
Windows 11 22H2-25H2 & Server 2022-2025 Privilege Escalation via Graphics TOCTOU
CVSS 7.0
Details
Vulnerabilities
704
Exploit Likelihood
Medium