CWE-367: CWE-367
Yearly Trend
Top Affected Vendors
All CWE-367 CVEs (175)
A TOCTOU vulnerability in containerd v2.1.0 allows specially crafted container images to modify the host filesystem during image unpacking. Only conta...
May 20, 2025A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Adobe Creative Cloud Desktop versions 6.7.0.278 and earlier allows low-privileged...
Oct 15, 2025A race condition vulnerability in CrowdStrike Falcon sensor for Windows allows attackers with existing code execution on a host to delete arbitrary fi...
Oct 8, 2025A local Time-of-check Time-of-use race condition vulnerability in Juniper Junos OS on MX10k Series allows low-privileged users to cause line card cras...
Jan 15, 2026A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Screen versions 5.0.0 and older 4.x releases allows local attackers to send SIGHU...
May 26, 2025This CVE describes an information disclosure vulnerability in Qualcomm virtualization components where a guest virtual machine may be able to access s...
Apr 7, 2025A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in the myCred WordPress plugin allows attackers to exploit timing gaps between permi...
Aug 14, 2025A race condition vulnerability in GitLab EE allows unauthorized cloning of private repositories when secondary nodes are out of sync. This affects all...
Jun 12, 2025This CVE describes a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Moxa's MXview One and MXview One Central Manager series. Attac...
Sep 21, 2024Dell PowerEdge Server BIOS contains a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability that allows a local low-privileged attacker to p...
Jun 25, 2024This vulnerability in MediaTek's WLAN STA driver allows local attackers to read memory beyond intended boundaries due to a race condition. It can lead...
Nov 4, 2025A race condition vulnerability in the Linux kernel's rainshadow-cec driver allows concurrent interrupt handlers to cause a buffer overflow. This affec...
Sep 5, 2025A race condition vulnerability in the Linux kernel's vsock subsystem allows a local attacker to cause a use-after-free condition when transport module...
Jul 25, 2025A race condition vulnerability in the Linux kernel's sk_is_readable() function can cause a null pointer dereference when sockets are removed from sock...
Jul 3, 2025A race condition vulnerability in the Linux kernel's Marvell PP2 network driver allows concurrent modifications to parser TCAM/SRAM memory, potentiall...
Apr 16, 2025This CVE describes a race condition in the Linux kernel's Open vSwitch conntrack module where attempting to allocate labels for confirmed conntrack en...
Apr 1, 2025A race condition vulnerability in the Linux kernel's Synaptics touchpad driver can cause a kernel crash when enabling pass-through ports. This affects...
Feb 27, 2025A race condition vulnerability in the Linux kernel's fork process where userfaultfd (UFFD) handlers can access incomplete or inconsistent virtual memo...
Nov 9, 2024This CVE describes a race condition vulnerability in the Linux kernel's DSA (Distributed Switch Architecture) subsystem during system shutdown. It can...
Oct 21, 2024A time-of-check time-of-use (TOCTOU) race condition vulnerability in ACAT software before version 3.13 allows authenticated local users to potentially...
Nov 11, 2025A TOCTOU race condition vulnerability in Dell PowerScale OneFS allows unauthenticated attackers with local access to cause denial of service or tamper...
May 8, 2025A TOCTOU race condition vulnerability in Outray (an open-source ngrok alternative) allows authenticated users to bypass subscription limits and create...
Jan 14, 2026A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Dell PowerScale OneFS allows low-privileged attackers with adjacent network acces...
Jan 22, 2026This vulnerability allows deactivated Mattermost users to learn team names they shouldn't have access to through a race condition in the API. It affec...
Feb 13, 2026This vulnerability allows attackers to bypass Keycloak's refresh token rotation security feature when strict rotation is enabled. Concurrent refresh r...
Jan 21, 2026About CWE-367 (CWE-367)
Our database tracks 175 CVEs classified as CWE-367, with 16 rated critical and 120 rated high severity. The average CVSS score for CWE-367 vulnerabilities is 7.2.
External reference: View CWE-367 on MITRE CWE →
Monitor CWE-367 Vulnerabilities
Get alerted when new CWE-367 CVEs affect your infrastructure.
Start Monitoring Free