CWE-367: CWE-367

174
Total CVEs
16
Critical
119
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
19
2025
62
2024
40
2023
32
2022
11

Top Affected Vendors

1 Microsoft 28
2 Qualcomm 17
3 Linux 13
4 Insyde 7
5 Hp 5
6 Debian 5
7 Adobe 4
8 Dell 4
9 Amd 4
10 Netapp 3

All CWE-367 CVEs (174)

CVE-2024-26218
7.8

This Windows kernel vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting a time-of-check-time...

Apr 9, 2024
CVE-2022-3701
7.8

A local privilege escalation vulnerability in Lenovo Vantage SystemUpdate plugin allows attackers to execute arbitrary code with elevated privileges. ...

Oct 27, 2023
CVE-2022-47631
7.8

CVE-2022-47631 is a local privilege escalation vulnerability in Razer Synapse software that allows attackers to gain administrative privileges on Wind...

Sep 14, 2023
CVE-2023-38141
7.8

This Windows kernel vulnerability allows local attackers to exploit a race condition (CWE-367) to elevate privileges from user mode to kernel mode. It...

Sep 12, 2023
CVE-2023-33154
7.8

This vulnerability in the Windows Partition Management Driver allows an authenticated attacker to execute arbitrary code with SYSTEM privileges. It af...

Jul 11, 2023
CVE-2023-1295
7.8

A time-of-check to time-of-use (TOCTOU) vulnerability in the Linux kernel's io_uring subsystem allows a local user to escalate privileges to root. Thi...

Jun 28, 2023
CVE-2022-31636
7.8

This CVE describes a time-of-check to time-of-use (TOCTOU) vulnerability in the BIOS of certain HP PC products. It could allow attackers to execute ar...

Jun 13, 2023
CVE-2022-31638
7.8

This CVE describes a time-of-check to time-of-use (TOCTOU) vulnerability in HP PC BIOS firmware that could allow attackers to execute arbitrary code, ...

Jun 13, 2023
CVE-2022-34899
7.8

This is a local privilege escalation vulnerability in Parallels Access Agent that allows attackers with initial low-privileged access to gain root pri...

Jul 18, 2022
CVE-2021-3969
7.8

A local privilege escalation vulnerability exists in Lenovo System Interface Foundation's IMController component due to a Time-of-Check Time-of-Use (T...

May 18, 2022
CVE-2021-36924
7.8

This vulnerability in Realtek RtsUpx USB Utility Driver allows local low-privileged users to execute arbitrary code with elevated privileges via a cra...

Nov 2, 2021
CVE-2020-11298
7.8

This vulnerability allows non-secure clients to modify permissions on shared memory buffers while the system is waiting for callback responses in Qual...

Jun 9, 2021
CVE-2020-1337
7.8

CVE-2020-1337 is a local privilege escalation vulnerability in the Windows Print Spooler service that allows authenticated attackers to write arbitrar...

Aug 17, 2020
CVE-2025-64645
7.7

A local privilege escalation vulnerability exists in IBM Concert due to a race condition involving symbolic link handling. This allows authenticated l...

Dec 26, 2025
CVE-2024-9183
7.7

This vulnerability in GitLab allows authenticated users to steal credentials from higher-privileged users and impersonate them under specific conditio...

Dec 5, 2025
CVE-2025-29833
7.7

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows Virtual Machine Bus allows local attackers to execute arbitrary code. Thi...

May 13, 2025
CVE-2026-25728
7.5

ClipBucket v5 versions before 5.5.3 - #40 have a TOCTOU race condition in avatar/background image uploads. Attackers can upload malicious PHP files th...

Feb 10, 2026
CVE-2025-62003
7.5

BullWall Server Intrusion Protection has a timing vulnerability where MFA checks for RDP connections have a configuration-dependent delay. Remote auth...

Dec 18, 2025
CVE-2025-62004
7.5

A local, authenticated attacker can log into BullWall Server Intrusion Protection systems during the brief window after boot when login services are r...

Dec 18, 2025
CVE-2025-20082
7.5

A time-of-check time-of-use race condition vulnerability in the UEFI firmware SmiVariable driver for specific Intel server boards allows a privileged ...

May 13, 2025
CVE-2025-29969
7.5

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows Fundamentals allows authenticated attackers to execute arbitrary code ove...

May 13, 2025
CVE-2024-42446
7.5

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in AMI's APTIOV BIOS firmware. An attacker with local access can ...

May 13, 2025
CVE-2024-54084
7.5

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in AMI's APTIOV BIOS firmware. An attacker with local access can ...

Mar 11, 2025
CVE-2024-41917
7.5

This CVE describes a time-of-check time-of-use (TOCTOU) race condition vulnerability in Intel Battery Life Diagnostic Tool software. An authenticated ...

Feb 12, 2025
CVE-2024-42444
7.5

CVE-2024-42444 is a TOCTOU race condition vulnerability in AMI APTIOV BIOS that allows local attackers to execute arbitrary code on affected devices. ...

Jan 14, 2025
CVE-2024-5803
7.5

This vulnerability allows a local attacker to escalate privileges via COM hijack in AVG/Avast Antivirus when self-protection is disabled. It affects u...

Oct 3, 2024
CVE-2023-20578
7.5

This CVE describes a TOCTOU (Time-Of-Check-Time-Of-Use) vulnerability in AMD System Management Mode (SMM) that could allow an attacker with ring0 priv...

Aug 13, 2024
CVE-2024-39894
7.5

This vulnerability in OpenSSH allows attackers to perform timing attacks against password entry when echo is disabled (e.g., during su or sudo operati...

Jul 2, 2024
CVE-2022-33270
7.5

This vulnerability is a time-of-check time-of-use (TOCTOU) race condition in Qualcomm modem firmware that allows a transient denial-of-service (DoS) a...

Apr 13, 2023
CVE-2022-0280
7.5

A race condition vulnerability in McAfee Total Protection's QuickClean feature allows local users to elevate privileges and delete arbitrary files. Th...

Mar 10, 2022
CVE-2021-34413
7.5

A Time-of-check Time-of-use (TOC/TOU) vulnerability in the Zoom Plugin for Microsoft Outlook on macOS allows standard users to write malicious applica...

Sep 27, 2021
CVE-2021-31422
7.5

This vulnerability allows local attackers with high-privileged code execution on a Parallels Desktop guest system to escalate privileges to hypervisor...

Apr 29, 2021
CVE-2025-69211
7.4

NestJS applications using Fastify platform with route-specific middleware are vulnerable to URL encoding bypass. This allows attackers to access prote...

Dec 29, 2025
CVE-2025-58407
7.4

This CVE describes a Time-of-Check Time-of-Use (TOCTOU) vulnerability in GPU firmware where guest VM kernel/driver software can post improper commands...

Nov 17, 2025
CVE-2024-29149
7.4

This CVE describes a time-of-check time-of-use (TOCTOU) vulnerability in Alcatel-Lucent ALE deskphones that allows authenticated attackers to replace ...

May 7, 2024
CVE-2021-26356
7.4

This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition in AMD's ASP bootloader that allows an attacker to tamper with SPI ROM data ...

May 9, 2023
CVE-2021-4098
7.4

This vulnerability allows a remote attacker who has already compromised Chrome's renderer process to potentially escape the browser sandbox via a craf...

Feb 11, 2022
CVE-2021-29657
7.4

This vulnerability allows an attacker with guest VM access on AMD systems to bypass host OS security controls and potentially execute arbitrary code o...

Jul 22, 2021
CVE-2026-23988
7.3

This CVE describes a time-of-check to time-of-use (TOCTOU) race condition vulnerability in Rufus versions 4.11 and below. When Rufus runs with Adminis...

Jan 22, 2026
CVE-2025-55236
7.3

A time-of-check time-of-use race condition vulnerability in the Graphics Kernel allows authenticated local attackers to execute arbitrary code. This a...

Sep 9, 2025
CVE-2024-10972
7.3

This vulnerability allows an attacker with administrative privileges to cause a Blue Screen of Death (BSOD) by manipulating memory access rights durin...

Dec 16, 2024
CVE-2023-3891
7.3

A race condition vulnerability in Lapce v0.2.8 allows attackers to execute arbitrary code with elevated privileges. This affects users running the vul...

Sep 15, 2023
CVE-2025-20037
7.2

A time-of-check time-of-use race condition vulnerability in Intel Converged Security and Management Engine firmware allows a privileged local user to ...

Aug 12, 2025
CVE-2024-22185
7.2

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in certain Intel processors with Intel ACTM technology. It allows...

Nov 13, 2024
CVE-2024-29066
7.2

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running Distributed File System (DFS) services. Attackers can ...

Apr 9, 2024
CVE-2023-32282
7.2

A race condition vulnerability in BIOS firmware for certain Intel processors allows a privileged user with local access to potentially escalate privil...

Mar 14, 2024
CVE-2023-29337
7.1

This vulnerability in the NuGet client allows remote code execution when processing specially crafted packages. Attackers could execute arbitrary code...

Jun 14, 2023
CVE-2025-61037
7.0

This CVE describes a local privilege escalation vulnerability in SevenCs ORCA G2 software where a TOCTOU race condition allows standard users to gain ...

Dec 31, 2025
CVE-2011-10035
7.0

This CVE describes a local privilege escalation vulnerability in Nagios XI where low-privileged users can exploit race conditions during crontab insta...

Oct 30, 2025
CVE-2025-59497
7.0

A time-of-check time-of-use race condition vulnerability in Microsoft Defender for Linux allows a local authenticated attacker to cause a denial of se...

Oct 14, 2025

About CWE-367 (CWE-367)

Our database tracks 174 CVEs classified as CWE-367, with 16 rated critical and 119 rated high severity. The average CVSS score for CWE-367 vulnerabilities is 7.2.

External reference: View CWE-367 on MITRE CWE →

Monitor CWE-367 Vulnerabilities

Get alerted when new CWE-367 CVEs affect your infrastructure.

Start Monitoring Free