CWE-367: CWE-367

175
Total CVEs
16
Critical
120
High
7.2
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
19
2025
62
2024
40
2023
32
2022
11

Top Affected Vendors

1 Microsoft 28
2 Qualcomm 17
3 Linux 13
4 Insyde 7
5 Debian 6
6 Hp 5
7 Adobe 4
8 Dell 4
9 Amd 4
10 Netapp 3

All CWE-367 CVEs (175)

CVE-2025-47290
5.9

A TOCTOU vulnerability in containerd v2.1.0 allows specially crafted container images to modify the host filesystem during image unpacking. Only conta...

May 20, 2025
CVE-2025-54271
5.6

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Creative Cloud Desktop versions 6.7.0.278 and earlier allows low-privileged...

Oct 15, 2025
CVE-2025-42701
5.6

A race condition vulnerability in CrowdStrike Falcon sensor for Windows allows attackers with existing code execution on a host to delete arbitrary fi...

Oct 8, 2025
CVE-2026-21912
5.5

A local Time-of-check Time-of-use race condition vulnerability in Juniper Junos OS on MX10k Series allows low-privileged users to cause line card cras...

Jan 15, 2026
CVE-2025-46805
5.5

A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Screen versions 5.0.0 and older 4.x releases allows local attackers to send SIGHU...

May 26, 2025
CVE-2025-21431
5.5

This CVE describes an information disclosure vulnerability in Qualcomm virtualization components where a guest virtual machine may be able to access s...

Apr 7, 2025
CVE-2025-54667
5.3

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in the myCred WordPress plugin allows attackers to exploit timing gaps between permi...

Aug 14, 2025
CVE-2024-9512
5.3

A race condition vulnerability in GitLab EE allows unauthorized cloning of private repositories when secondary nodes are out of sync. This affects all...

Jun 12, 2025
CVE-2024-6787
5.3

This CVE describes a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Moxa's MXview One and MXview One Central Manager series. Attac...

Sep 21, 2024
CVE-2024-0171
5.3

Dell PowerEdge Server BIOS contains a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability that allows a local low-privileged attacker to p...

Jun 25, 2024
CVE-2025-20740
4.7

This vulnerability in MediaTek's WLAN STA driver allows local attackers to read memory beyond intended boundaries due to a race condition. It can lead...

Nov 4, 2025
CVE-2025-39713
4.7

A race condition vulnerability in the Linux kernel's rainshadow-cec driver allows concurrent interrupt handlers to cause a buffer overflow. This affec...

Sep 5, 2025
CVE-2025-38461
4.7

A race condition vulnerability in the Linux kernel's vsock subsystem allows a local attacker to cause a use-after-free condition when transport module...

Jul 25, 2025
CVE-2025-38112
4.7

A race condition vulnerability in the Linux kernel's sk_is_readable() function can cause a null pointer dereference when sockets are removed from sock...

Jul 3, 2025
CVE-2025-22060
4.7

A race condition vulnerability in the Linux kernel's Marvell PP2 network driver allows concurrent modifications to parser TCAM/SRAM memory, potentiall...

Apr 16, 2025
CVE-2025-21958
4.7

This CVE describes a race condition in the Linux kernel's Open vSwitch conntrack module where attempting to allocate labels for confirmed conntrack en...

Apr 1, 2025
CVE-2025-21746
4.7

A race condition vulnerability in the Linux kernel's Synaptics touchpad driver can cause a kernel crash when enabling pass-through ports. This affects...

Feb 27, 2025
CVE-2024-50220
4.7

A race condition vulnerability in the Linux kernel's fork process where userfaultfd (UFFD) handlers can access incomplete or inconsistent virtual memo...

Nov 9, 2024
CVE-2024-49998
4.7

This CVE describes a race condition vulnerability in the Linux kernel's DSA (Distributed Switch Architecture) subsystem during system shutdown. It can...

Oct 21, 2024
CVE-2025-27725
4.4

A time-of-check time-of-use (TOCTOU) race condition vulnerability in ACAT software before version 3.13 allows authenticated local users to potentially...

Nov 11, 2025
CVE-2025-30101
4.4

A TOCTOU race condition vulnerability in Dell PowerScale OneFS allows unauthenticated attackers with local access to cause denial of service or tamper...

May 8, 2025
CVE-2026-22820
3.7

A TOCTOU race condition vulnerability in Outray (an open-source ngrok alternative) allows authenticated users to bypass subscription limits and create...

Jan 14, 2026
CVE-2026-22281
3.5

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Dell PowerScale OneFS allows low-privileged attackers with adjacent network acces...

Jan 22, 2026
CVE-2026-20796
3.1

This vulnerability allows deactivated Mattermost users to learn team names they shouldn't have access to through a race condition in the API. It affec...

Feb 13, 2026
CVE-2026-1035
3.1

This vulnerability allows attackers to bypass Keycloak's refresh token rotation security feature when strict rotation is enabled. Concurrent refresh r...

Jan 21, 2026

About CWE-367 (CWE-367)

Our database tracks 175 CVEs classified as CWE-367, with 16 rated critical and 120 rated high severity. The average CVSS score for CWE-367 vulnerabilities is 7.2.

External reference: View CWE-367 on MITRE CWE →

Monitor CWE-367 Vulnerabilities

Get alerted when new CWE-367 CVEs affect your infrastructure.

Start Monitoring Free