Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

722 CVEs tagged with CWE-36728 Critical, 365 High, 282 Medium, 47 Low, 0 Unrated.

CVE-2025-55696

Published Oct 14, 2025

Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-55680

Published Oct 14, 2025

Time-of-check time-of-use (toctou) race condition in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-42701

Published Oct 8, 2025

A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike rel…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-58131

Published Sep 9, 2025

Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may all…

CVSS 6.6 · Medium

CVE-2025-55236

Published Sep 9, 2025

Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-39713

Published Sep 5, 2025

In the Linux kernel, the following vulnerability has been resolved: media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() In the interrupt handler rain_interrupt(…

CVSS 4.7 · Medium
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort

CVE-2025-9810

Published Sep 1, 2025

TOCTOU  in linenoiseHistorySave in linenoise allows local attackers to overwrite arbitrary files and change permissions via a symlink race between fopen("w") on the history path a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-44002

Published Aug 26, 2025

Race Condition in the Directory Validation Logic in the TeamViewer Full Client and Host prior version 15.69 on Windows allows a local non-admin user to create arbitrary files with…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-54667

Published Aug 14, 2025

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred mycred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions.This issue aff…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-53788

Published Aug 12, 2025

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49558

Published Aug 12, 2025

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerabi…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-20074

Published Aug 12, 2025

Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potenti…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-20037

Published Aug 12, 2025

Time-of-check time-of-use race condition in firmware for some Intel(R) Converged Security and Management Engine may allow a privileged user to potentially enable escalation of pri…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-54655

Published Aug 6, 2025

Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and integrity of the virtualization gr…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-23279

Published Aug 2, 2025

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerabilit…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-8192

Published Jul 31, 2025

There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied activity in Settings’ context, i.e. system-uid context, thu…

CVSS 6.9 · Medium

CVE-2025-43276

Published Jul 30, 2025

A logic error was addressed with improved error handling. This issue is fixed in macOS Sequoia 15.6. iCloud Private Relay may not activate when more than one user is logged in at…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-38462

Published Jul 25, 2025

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.…

CVSS 4.7 · Medium
evidence mentions
9
Buzz score
33.0
Vendor/product tagsBeta · best-effort
Showing 251-275 of 722 CVEsPage 11 of 29