Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

697 CVEs tagged with CWE-36727 Critical, 353 High, 270 Medium, 47 Low, 0 Unrated.

CVE-2025-53594

Published Jan 2, 2026

A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the…

CVSS 4.4 · Medium

CVE-2025-61037

Published Dec 31, 2025

A local privilege escalation vulnerability exists in SevenCs ORCA G2 2.0.1.35 (EC2007 Kernel v5.22). The flaw is a Time-of-Check Time-of-Use (TOCTOU) race condition in the license…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-69211

Published Dec 29, 2025

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulner…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64645

Published Dec 26, 2025

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34290

Published Dec 20, 2025

Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client commun…

CVSS 8.5 · High

CVE-2025-62004

Published Dec 18, 2025

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local, authenticated attacker can log in after boot and before SI…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62003

Published Dec 18, 2025

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connections. A remote, authenticated attacker can potentially bypa…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68146

Published Dec 16, 2025

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or trun…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-9183

Published Dec 5, 2025

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenti…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62724

Published Nov 20, 2025

Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time of Use" (TOCTOU) attack when downloading zip files to acce…

CVSS 4.3 · Medium

CVE-2025-58407

Published Nov 17, 2025

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31146

Published Nov 11, 2025

Time-of-check time-of-use race condition for some Intel Ethernet Adapter Complete Driver Pack software before version 1.5.1.0 within Ring 3: User Applications may allow a denial o…

CVSS 5.1 · Medium

CVE-2025-27725

Published Nov 11, 2025

Time-of-check time-of-use race condition for some ACAT before version 3.13 within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an…

CVSS 4.1 · Medium

CVE-2025-64180

Published Nov 7, 2025

Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vulnerability permits unauthorized access to internal network…

CVSS 10.0 · Critical

CVE-2011-10035

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use ra…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-64118

Published Oct 30, 2025

node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk…

CVSS 6.1 · Medium

CVE-2025-62511

Published Oct 17, 2025

yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condi…

CVSS 6.3 · Medium

CVE-2025-54271

Published Oct 15, 2025

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system wr…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 697 CVEsPage 9 of 28