CWE-367: CWE-367

175
Total CVEs
16
Critical
120
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
19
2025
62
2024
40
2023
32
2022
11

Top Affected Vendors

1 Microsoft 28
2 Qualcomm 17
3 Linux 13
4 Insyde 7
5 Debian 6
6 Hp 5
7 Adobe 4
8 Dell 4
9 Amd 4
10 Netapp 3

All CWE-367 CVEs (175)

CVE-2025-59497
7.0

A time-of-check time-of-use race condition vulnerability in Microsoft Defender for Linux allows a local authenticated attacker to cause a denial of se...

Oct 14, 2025
CVE-2025-59261
7.0

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Microsoft Graphics Component allows authenticated attackers to elevate privileges...

Oct 14, 2025
CVE-2025-54093
7.0

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows TCP/IP stack allows authenticated local attackers to elevate privileges b...

Sep 9, 2025
CVE-2025-50158
7.0

A time-of-check time-of-use race condition vulnerability in Windows NTFS allows local attackers to read unauthorized files or memory contents. This af...

Aug 12, 2025
CVE-2025-23279
7.0

A race condition vulnerability in NVIDIA .run installers for Linux and Solaris allows local attackers to escalate privileges. This affects systems whe...

Aug 2, 2025
CVE-2025-24036
7.0

This vulnerability in Microsoft AutoUpdate (MAU) allows attackers to gain elevated privileges on affected systems. It affects macOS devices running Mi...

Feb 11, 2025
CVE-2024-50234
7.0

A race condition vulnerability in the Linux kernel's iwlegacy WiFi driver allows stale interrupts to trigger during system resume from hibernation, ca...

Nov 9, 2024
CVE-2024-50592
7.0

This CVE describes a local privilege escalation vulnerability in Elefant Update Service where an attacker with local access can exploit a race conditi...

Nov 8, 2024
CVE-2024-39425
7.0

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Acrobat Reader that could allow local attackers to escal...

Aug 14, 2024
CVE-2024-39420
7.0

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Acrobat Reader that could allow arbitrary code execution...

Aug 14, 2024
CVE-2024-35265
7.0

This vulnerability allows an authenticated attacker to elevate privileges on Windows systems by exploiting the Windows Perception Service. It affects ...

Jun 11, 2024
CVE-2021-47280
7.0

This CVE describes a use-after-free vulnerability in the Linux kernel's Direct Rendering Manager (DRM) subsystem. Attackers could potentially exploit ...

May 21, 2024
CVE-2024-26974
7.0

This CVE describes a use-after-free vulnerability in the Linux kernel's Intel QAT crypto driver during PCI AER error recovery. A race condition occurs...

May 1, 2024
CVE-2021-33632
7.0

This CVE describes a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in openEuler iSulad container runtime. It allows attackers to exp...

Mar 25, 2024
CVE-2024-21433
7.0

This vulnerability allows attackers to elevate privileges on Windows systems by exploiting the Print Spooler service. Attackers could gain SYSTEM-leve...

Mar 12, 2024
CVE-2022-48618
7.0

This vulnerability allows an attacker with arbitrary read/write capability to bypass Pointer Authentication security mechanisms on Apple devices. It a...

Jan 9, 2024
CVE-2023-38041
7.0

CVE-2023-38041 is a privilege escalation vulnerability in Ivanti software where authenticated users can exploit a Time-of-Check to Time-of-Use (TOCTOU...

Oct 25, 2023
CVE-2023-27470
7.0

This vulnerability in N-able Take Control Agent allows attackers to delete arbitrary files through a time-of-check to time-of-use (TOCTOU) race condit...

Sep 11, 2023
CVE-2023-35378
7.0

This vulnerability in Windows Projected File System allows attackers to elevate privileges on affected systems. It enables local authenticated users t...

Aug 8, 2023
CVE-2023-26299
7.0

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in AMI UEFI Firmware on certain HP PC products could allow attackers to execute arbitrary code d...

Jun 30, 2023
CVE-2023-32554
7.0

This CVE describes a Time-of-Check Time-of-Use (TOCTOU) vulnerability in Trend Micro Apex One and Apex One as a Service agents that allows local attac...

Jun 26, 2023
CVE-2022-4149
7.0

This vulnerability allows a local unprivileged Windows user to exploit a race condition in the Netskope client service to gain SYSTEM-level privileges...

Jun 15, 2023
CVE-2022-31641
7.0

This CVE describes vulnerabilities in the system BIOS of certain HP PC products that could allow attackers to execute arbitrary code, escalate privile...

Jun 14, 2023
CVE-2023-24861
7.0

CVE-2023-24861 is a privilege escalation vulnerability in the Windows Graphics Component that allows authenticated attackers to gain SYSTEM-level priv...

Mar 14, 2023
CVE-2022-32477
7.0

This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on a shared buffer between SMM and non-SMM code, creating a TOCTOU race condition. ...

Feb 15, 2023
CVE-2022-32469
7.0

This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the PnpSmm shared buffer, creating TOCTOU race conditions that can corrupt SMRAM...

Feb 15, 2023
CVE-2022-32473
7.0

This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the HddPassword shared buffer, creating TOCTOU race conditions that can corrupt ...

Feb 15, 2023
CVE-2022-32953
7.0

This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the SdHostDriver buffer, creating TOCTOU race conditions that can corrupt SMRAM ...

Feb 15, 2023
CVE-2022-32471
7.0

This vulnerability in InsydeH2O firmware allows attackers with local access to potentially escalate privileges or corrupt data by exploiting a time-of...

Feb 15, 2023
CVE-2022-32478
7.0

This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on a shared buffer between SMM and non-SMM code, creating a TOCTOU race condition. ...

Feb 15, 2023
CVE-2022-32955
7.0

This vulnerability in Insyde InsydeH2O firmware allows DMA attacks on the NvmExpressDxe buffer, creating TOCTOU race conditions that can corrupt SMRAM...

Feb 15, 2023
CVE-2022-43779
7.0

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in AMI UEFI Firmware used in certain HP PC products could allow attackers to execute arbitrary c...

Feb 12, 2023
CVE-2022-1537
7.0

CVE-2022-1537 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in GruntJS's file.copy operations that allows arbitrary file writes...

May 10, 2022
CVE-2022-23181
7.0

This CVE describes a time-of-check-time-of-use (TOCTOU) vulnerability in Apache Tomcat that allows local attackers to escalate privileges. The vulnera...

Jan 27, 2022
CVE-2021-34788
7.0

This vulnerability allows authenticated local attackers to execute arbitrary code with root privileges on Linux and Mac OS systems running Cisco AnyCo...

Oct 6, 2021
CVE-2021-1567
7.0

This vulnerability allows an authenticated local attacker to perform DLL hijacking through a race condition in Cisco AnyConnect's signature verificati...

Jun 16, 2021
CVE-2025-48818
6.8

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Windows BitLocker allows an attacker with physical access to bypass security feat...

Jul 8, 2025
CVE-2024-39826
6.8

A race condition vulnerability in Zoom Workplace Team Chat for Windows allows authenticated users to potentially access sensitive information through ...

Jul 15, 2024
CVE-2025-13818
6.7

This vulnerability allows local attackers to escalate privileges by exploiting insecure temporary batch file execution in ESET Management Agent. Attac...

Feb 6, 2026
CVE-2025-47344
6.7

This CVE describes a memory corruption vulnerability in Qualcomm sensor utility operations that could allow attackers to execute arbitrary code or cau...

Jan 7, 2026
CVE-2025-47332
6.7

This vulnerability involves memory corruption when processing configuration calls from userspace in Qualcomm components, potentially allowing local at...

Jan 7, 2026
CVE-2024-53016
6.6

This vulnerability allows memory corruption in Qualcomm camera drivers when processing I2C settings. Attackers could potentially execute arbitrary cod...

Jun 3, 2025
CVE-2024-53018
6.6

This vulnerability involves memory corruption in the OIS packet parser, which could allow an attacker to execute arbitrary code or cause denial of ser...

Jun 3, 2025
CVE-2025-3599
6.5

This CVE describes an Elevation of Privilege vulnerability in Symantec Endpoint Protection Windows Agent's ERASER Engine that allows attackers to dele...

Apr 30, 2025
CVE-2024-51563
6.5

This CVE describes a time-of-check to time-of-use (TOCTOU) race condition in the virtio_vq_recordon function in bhyve's virtual I/O implementation. It...

Nov 12, 2024
CVE-2026-27127
6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Craft CMS's GraphQL Asset mutation that allows DNS rebinding attacks. Attacke...

Feb 24, 2026
CVE-2025-62511
6.3

This vulnerability allows local attackers with write access to the application's configuration directory to exploit a TOCTOU race condition during con...

Oct 17, 2025
CVE-2025-31146
6.1

A time-of-check time-of-use race condition vulnerability in Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 allows unprivi...

Nov 11, 2025
CVE-2025-44002
6.1

A race condition vulnerability in TeamViewer's directory validation logic allows local non-admin users to create arbitrary files with SYSTEM privilege...

Aug 26, 2025
CVE-2025-49558
5.9

This CVE describes a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Commerce that allows attackers to bypass security featur...

Aug 12, 2025

About CWE-367 (CWE-367)

Our database tracks 175 CVEs classified as CWE-367, with 16 rated critical and 120 rated high severity. The average CVSS score for CWE-367 vulnerabilities is 7.2.

External reference: View CWE-367 on MITRE CWE →

Monitor CWE-367 Vulnerabilities

Get alerted when new CWE-367 CVEs affect your infrastructure.

Start Monitoring Free