Skip to content
Noroxi

CWE-367 · 773 records

Time-of-check Time-of-use (TOCTOU) Race Condition

CVEs in this class

776 records

  • CVE-2024-30088
    78This week

    Windows Kernel Elevation of Privilege Vulnerability

    HighCVSS 7.0KEVWeaponizedEPSS 68%

    microsoft · windows 10 1507Jun 11, 2024

  • CVE-2023-35311
    70This week

    Microsoft Outlook Security Feature Bypass Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 16%

    microsoft · 365 appsJul 11, 2023

  • CVE-2025-22224
    62This week

    VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write.

    HighCVSS 8.2KEVWeaponizedEPSS 2%

    vmware · esxiMar 4, 2025

  • CVE-2025-38352
    61This week

    posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()

    HighCVSS 7.8KEVWeaponizedEPSS 1%

    linux · linux kernelJul 22, 2025

  • The issue was addressed with improved checks.

    HighCVSS 7.0KEVWeaponizedEPSS 0%

    apple · ipadosJan 9, 2024

  • This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490.

    HighCVSS 8.1No exploitEPSS 83%

    ivanti · avalancheMar 29, 2023

  • Versa Concerto Authentication Bypass File Write Remote Code Execution

    CriticalCVSS 10.0Proof of conceptEPSS 45%

    versa-networks · concertoMay 21, 2025

  • Apache Tomcat: RCE due to TOCTOU issue in JSP compilation

    CriticalCVSS 9.8Proof of conceptEPSS 32%

    apache · tomcatDec 17, 2024

  • Windows Themes Remote Code Execution Vulnerability

    HighCVSS 8.8WeaponizedEPSS 37%

    microsoft · windows 11 21h2Sep 12, 2023

  • NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration

    HighCVSS 8.3Proof of conceptEPSS 41%

    nvidia · nvidia container toolkitSep 26, 2024

  • Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete

    CriticalCVSS 9.8No exploitEPSS 9%

    apache · tomcatDec 20, 2024

  • In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one use

    CriticalCVSS 9.8No exploitEPSS 3%

    keybase · keybaseJan 31, 2019

  • Manager-io/Manager: Complete Bypass of SSRF Protection via Time-of-Check Time-of-Use (TOCTOU)

    CriticalCVSS 10.0No exploitEPSS 0%

    manager-io · managerNov 7, 2025

  • Windows Registry Elevation of Privilege Vulnerability

    HighCVSS 7.5No exploitEPSS 28%

    microsoft · windows 10 1809Nov 12, 2024

  • CVE-2019-5421
    39Monitor

    Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devise::Models::Lockable`

    CriticalCVSS 9.8No exploitEPSS 2%

    plataformatec · deviseApr 3, 2019

  • An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.

    CriticalCVSS 9.8No exploitEPSS 1%

    openstack · magnumApr 12, 2024

  • Windows Partition Management Driver Elevation of Privilege Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    microsoft · windows 10 1507Jul 11, 2023

  • batman-adv: tt: fix TOCTOU race for reported vlans

    CriticalCVSS 9.8No exploitEPSS 1%

    linux · linux kernelJul 19, 2026

  • A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root

    CriticalCVSS 9.9No exploitEPSS 0%

    webpros · pleskSep 10, 2026

  • Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge

    CriticalCVSS 9.9No exploitEPSS 0%

    canonical · lxdAug 12, 2026

  • Duplicate Advisory: OpenClaw: Node pairing reconnection could confuse approval scope state

    CriticalCVSS 9.8No exploit

    npm · openclawJun 13, 2026

  • TOCTOU Vulnerability in file exchange

    CriticalCVSS 9.3No exploitEPSS 1%

    sauter · modu680-asSep 1, 2026

  • ClipBucket v5 Affected by Remote Code Execution via Avatar/Background File Upload Race Condition

    CriticalCVSS 9.3No exploitEPSS 0%

    oxygenz · clipbucketFeb 10, 2026

  • n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users

    CriticalCVSS 9.4No exploitEPSS 0%

    n8n · n8nFeb 4, 2026

  • varstored: TOCTOU issues with mapped guest memory

    CriticalCVSS 9.4No exploitEPSS 0%

    xen · varstoredJul 9, 2026

All vulnerability classes