CWE-367 · 773 records
Time-of-check Time-of-use (TOCTOU) Race Condition
CVEs in this class
776 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
78This week | CVE-2024-30088Weaponized | Windows Kernel Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-367 | High7.0 | KEV | 68.2% | Jun 11, 2024 |
70This week | CVE-2023-35311Weaponized | Microsoft Outlook Security Feature Bypass Vulnerabilitymicrosoft · 365 apps · CWE-367 | High8.8 | KEV | 15.5% | Jul 11, 2023 |
62This week | CVE-2025-22224Weaponized | VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write.vmware · esxi · CWE-367 | High8.2 | KEV | 1.6% | Mar 4, 2025 |
61This week | CVE-2025-38352Weaponized | posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()linux · linux kernel · CWE-367 | High7.8 | KEV | 1.3% | Jul 22, 2025 |
58Plan | CVE-2022-48618Weaponized | The issue was addressed with improved checks.apple · ipados · CWE-367 | High7.0 | KEV | 0.5% | Jan 9, 2024 |
57Plan | CVE-2022-36980No exploit | This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490.ivanti · avalanche · CWE-367 | High8.1 | — | 83.1% | Mar 29, 2023 |
54Plan | CVE-2025-34027Proof of concept | Versa Concerto Authentication Bypass File Write Remote Code Executionversa-networks · concerto · CWE-367 | Critical10.0 | — | 45.2% | May 21, 2025 |
49Plan | CVE-2024-50379Proof of concept | Apache Tomcat: RCE due to TOCTOU issue in JSP compilationapache · tomcat · CWE-367 | Critical9.8 | — | 31.8% | Dec 17, 2024 |
46Plan | CVE-2023-38146Weaponized | Windows Themes Remote Code Execution Vulnerabilitymicrosoft · windows 11 21h2 · CWE-367 | High8.8 | — | 37.4% | Sep 12, 2023 |
45Plan | CVE-2024-0132Proof of concept | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration nvidia · nvidia container toolkit · CWE-367 | High8.3 | — | 40.8% | Sep 26, 2024 |
42Plan | CVE-2024-56337No exploit | Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incompleteapache · tomcat · CWE-367 | Critical9.8 | — | 9.0% | Dec 20, 2024 |
40Plan | CVE-2019-7249No exploit | In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one usekeybase · keybase · CWE-367 | Critical9.8 | — | 2.5% | Jan 31, 2019 |
40Plan | CVE-2025-64180No exploit | Manager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)manager-io · manager · CWE-367 | Critical10.0 | — | 0.3% | Nov 7, 2025 |
39Monitor | CVE-2024-43452No exploit | Windows Registry Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1809 · CWE-367 | High7.5 | — | 28.4% | Nov 12, 2024 |
39Monitor | CVE-2019-5421No exploit | Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable`plataformatec · devise · CWE-367 | Critical9.8 | — | 1.6% | Apr 3, 2019 |
39Monitor | CVE-2024-28718No exploit | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.openstack · magnum · CWE-367 | Critical9.8 | — | 1.1% | Apr 12, 2024 |
39Monitor | CVE-2023-33154No exploit | Windows Partition Management Driver Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-367 | Critical9.8 | — | 0.8% | Jul 11, 2023 |
39Monitor | CVE-2026-64091No exploit | batman-adv: tt: fix TOCTOU race for reported vlanslinux · linux kernel · CWE-367 | Critical9.8 | — | 0.6% | Jul 19, 2026 |
39Monitor | CVE-2026-68488No exploit | A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to rootwebpros · plesk · CWE-367 | Critical9.9 | — | 0.4% | Sep 10, 2026 |
39Monitor | CVE-2026-63297No exploit | Cross-project instance copy bypasses target project restrictions via TOCTOU in config mergecanonical · lxd · CWE-367 | Critical9.9 | — | 0.3% | Aug 12, 2026 |
39Monitor | GHSA-c85p-9pvr-f7f5No exploit | Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope statenpm · openclaw · CWE-367 | Critical9.8 | — | — | Jun 13, 2026 |
37Monitor | CVE-2026-78319No exploit | TOCTOU Vulnerability in file exchangesauter · modu680-as · CWE-367 | Critical9.3 | — | 0.6% | Sep 1, 2026 |
37Monitor | CVE-2026-25728No exploit | ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Conditionoxygenz · clipbucket · CWE-367 | Critical9.3 | — | 0.4% | Feb 10, 2026 |
37Monitor | CVE-2026-25052No exploit | n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Usersn8n · n8n · CWE-367 | Critical9.4 | — | 0.3% | Feb 4, 2026 |
37Monitor | CVE-2025-58151No exploit | varstored: TOCTOU issues with mapped guest memoryxen · varstored · CWE-367 | Critical9.4 | — | 0.1% | Jul 9, 2026 |
- CVE-2024-3008878This week
Windows Kernel Elevation of Privilege Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 68%microsoft · windows 10 1507Jun 11, 2024
- CVE-2023-3531170This week
Microsoft Outlook Security Feature Bypass Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 16%microsoft · 365 appsJul 11, 2023
- CVE-2025-2222462This week
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write.
HighCVSS 8.2KEVWeaponizedEPSS 2%vmware · esxiMar 4, 2025
- CVE-2025-3835261This week
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
HighCVSS 7.8KEVWeaponizedEPSS 1%linux · linux kernelJul 22, 2025
- CVE-2022-4861858Plan
The issue was addressed with improved checks.
HighCVSS 7.0KEVWeaponizedEPSS 0%apple · ipadosJan 9, 2024
- CVE-2022-3698057Plan
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490.
HighCVSS 8.1No exploitEPSS 83%ivanti · avalancheMar 29, 2023
- CVE-2025-3402754Plan
Versa Concerto Authentication Bypass File Write Remote Code Execution
CriticalCVSS 10.0Proof of conceptEPSS 45%versa-networks · concertoMay 21, 2025
- CVE-2024-5037949Plan
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation
CriticalCVSS 9.8Proof of conceptEPSS 32%apache · tomcatDec 17, 2024
- CVE-2023-3814646Plan
Windows Themes Remote Code Execution Vulnerability
HighCVSS 8.8WeaponizedEPSS 37%microsoft · windows 11 21h2Sep 12, 2023
- CVE-2024-013245Plan
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration
HighCVSS 8.3Proof of conceptEPSS 41%nvidia · nvidia container toolkitSep 26, 2024
- CVE-2024-5633742Plan
Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete
CriticalCVSS 9.8No exploitEPSS 9%apache · tomcatDec 20, 2024
- CVE-2019-724940Plan
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one use
CriticalCVSS 9.8No exploitEPSS 3%keybase · keybaseJan 31, 2019
- CVE-2025-6418040Plan
Manager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)
CriticalCVSS 10.0No exploitEPSS 0%manager-io · managerNov 7, 2025
- CVE-2024-4345239Monitor
Windows Registry Elevation of Privilege Vulnerability
HighCVSS 7.5No exploitEPSS 28%microsoft · windows 10 1809Nov 12, 2024
- CVE-2019-542139Monitor
Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable`
CriticalCVSS 9.8No exploitEPSS 2%plataformatec · deviseApr 3, 2019
- CVE-2024-2871839Monitor
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.
CriticalCVSS 9.8No exploitEPSS 1%openstack · magnumApr 12, 2024
- CVE-2023-3315439Monitor
Windows Partition Management Driver Elevation of Privilege Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%microsoft · windows 10 1507Jul 11, 2023
- CVE-2026-6409139Monitor
batman-adv: tt: fix TOCTOU race for reported vlans
CriticalCVSS 9.8No exploitEPSS 1%linux · linux kernelJul 19, 2026
- CVE-2026-6848839Monitor
A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root
CriticalCVSS 9.9No exploitEPSS 0%webpros · pleskSep 10, 2026
- CVE-2026-6329739Monitor
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
CriticalCVSS 9.9No exploitEPSS 0%canonical · lxdAug 12, 2026
- GHSA-c85p-9pvr-f7f539Monitor
Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state
CriticalCVSS 9.8No exploitnpm · openclawJun 13, 2026
- CVE-2026-7831937Monitor
TOCTOU Vulnerability in file exchange
CriticalCVSS 9.3No exploitEPSS 1%sauter · modu680-asSep 1, 2026
- CVE-2026-2572837Monitor
ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Condition
CriticalCVSS 9.3No exploitEPSS 0%oxygenz · clipbucketFeb 10, 2026
- CVE-2026-2505237Monitor
n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
CriticalCVSS 9.4No exploitEPSS 0%n8n · n8nFeb 4, 2026
- CVE-2025-5815137Monitor
varstored: TOCTOU issues with mapped guest memory
CriticalCVSS 9.4No exploitEPSS 0%xen · varstoredJul 9, 2026