Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

697 CVEs tagged with CWE-36727 Critical, 353 High, 270 Medium, 47 Low, 0 Unrated.

CVE-2025-55696

Published Oct 14, 2025

Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High

CVE-2025-55680

Published Oct 14, 2025

Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High

CVE-2025-42701

Published Oct 8, 2025

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike rel…

CVSS 5.6 · Medium

CVE-2025-58131

Published Sep 9, 2025

Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may all…

CVSS 6.6 · Medium

CVE-2025-39713

Published Sep 5, 2025

In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() In the interrupt handler rain_interrupt(…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-9810

Published Sep 1, 2025

TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-44002

Published Aug 26, 2025

Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows allows a local non-admin user to create arbitrary files with…

CVSS 6.1 · Medium

CVE-2025-54667

Published Aug 14, 2025

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred mycred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions.This issue aff…

CVSS 5.3 · Medium

CVE-2025-20074

Published Aug 12, 2025

Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potenti…

CVSS 7.3 · High

CVE-2025-20037

Published Aug 12, 2025

Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of pri…

CVSS 6.8 · Medium

CVE-2025-54655

Published Aug 6, 2025

Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization gr…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-23279

Published Aug 2, 2025

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerabilit…

CVSS 7.0 · High

CVE-2025-8192

Published Jul 31, 2025

There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thu…

CVSS 6.9 · Medium

CVE-2025-43276

Published Jul 30, 2025

A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-38462

Published Jul 25, 2025

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 697 CVEsPage 10 of 28