VulnSea

CWE-367

CVEs classified under CWE-367, newest first.

174 CVEsRSS

CVE-2026-63334Medium· 6.8PoC
yesterday

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java perfor…

Twilightjgraph · drawiovia NVD
CVE-2026-55567High· 7.8PoC
yesterday

BleachBit cleans files to free disk space and to maintain privacy

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory w…

Midnightbleachbit · bleachbitvia NVD
CVE-2026-93380Low· 3.1
5d ago

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chrom…

Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-45720High· 7.0
5d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state ope…

Twilightsiderolabs · omniEPSS 0.11%via NVD
CVE-2026-54587Medium· 5.8
5d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local a…

SunlitMidnightBSD · mportEPSS 0.10%via NVD
CVE-2026-54576Medium· 5.8
5d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with wr…

SunlitMidnightBSD · mportEPSS 0.10%via NVD
CVE-2026-54575Medium· 5.8
5d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c…

SunlitMidnightBSD · mportEPSS 0.12%via NVD
CVE-2026-86861Medium· 5.9
5d ago

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call

pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-…

Sunlitpgadmin · pgadmin_4EPSS 0.44%via NVD
CVE-2026-82761Critical· 9.1
5d ago

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configur…

Midnightteam-alembic · ash_authenticationEPSS 0.40%via NVD
CVE-2026-25278High· 7.8
5d ago

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

TwilightQualcomm, Inc. · SnapdragonEPSS 0.09%via NVD
CVE-2026-77955Medium· 4.4
6d ago

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

SunlitNLnet Labs · UnboundEPSS 0.13%via NVD
CVE-2024-11222Medium· 6.4
6d ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context…

SunlitGitLab · GitLabEPSS 0.28%via NVD
CVE-2026-91748High· 8.3
1w ago

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox …

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox …

Twilightgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91744Medium· 5.3
1w ago

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTM…

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTM…

Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91743High· 8.3
1w ago

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security sever…

Twilightgoogle · chromeEPSS 0.25%via NVD
CVE-2026-91712High· 8.3
1w ago

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromiu…

Twilightgoogle · chromeEPSS 0.27%via NVD
CVE-2026-91708Low· 3.1⚖ disputed
1w ago

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.16%via NVD
CVE-2026-79994High· 8.7
1w ago

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlin…

TwilightDocker · Docker SandboxesEPSS 0.11%via NVD
CVE-2026-58716Medium· 6.7
1w ago

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.06%via NVD
CVE-2026-40058High· 8.8
1w ago

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows

CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers rema…

TwilightCrowdStrike · Falcon sensor for WindowsEPSS 0.08%via NVD
CVE-2026-77972Critical· 9.0
1w ago

Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the addre…

Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the addre…

MidnightSlab · safeurlEPSS 0.32%via NVD
CVE-2026-18069Medium· 6.0
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a time-of-check to time-of-use (TOCTOU) race condition.

SunlitIBM · iEPSS 0.13%via NVD
CVE-2026-86836High· 8.4
1w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a dir…

TwilightEclipse Foundation · Eclipse AnkaiosEPSS 0.09%via NVD
CVE-2022-42917Medium· 6.7
1w ago

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the owner…

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the owner…

SunlitFRRouting · FRRoutingEPSS 0.13%via NVD
CVE-2026-23786Low· 2.8
1w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.

SunlitSamsung · Exynos 1280 firmwareEPSS 0.08%via NVD
CVE-2026-82430High· 7.8
1w ago

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the …

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the …

TwilightApache Software Foundation · org.apache.storm:storm-coreEPSS 0.14%via NVD
CVE-2026-82429High· 7.8
1w ago

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid…

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid…

TwilightApache Software Foundation · org.apache.storm:storm-coreEPSS 0.13%via NVD
CVE-2026-53708Medium· 6.6PoC
1w ago

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs

ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs. Prior to 1.0.3, the /admin/gateways/test call site in mcpgateway/admin.py calls valid…

TwilightIBM · mcp-context-forgeEPSS 0.28%via NVD
CVE-2026-89523High· 7.0⚖ disputed
1w ago

kernel: wifi: mt76: mt7925: cancel pending mlo_pm_work (CVE-2026-89523)

A flaw was found in the Linux kernel's MediaTek mt7925 Wi-Fi driver. When the device is reset, suspended, or unregistered, a pending work item (`mlo_pm_work`) can continue to execute. This can lead to the work item accessing memory that ha…

TwilightRed Hat · Red Hat Enterprise Linux 9EPSS 0.14%via CSAF
CVE-2026-89521Medium· 5.5
1w ago

kernel: sched/core: Handle pick_task() releasing the rq lock (CVE-2026-89521)

A flaw was found in the Linux kernel's core scheduling component. This issue occurs when the `pick_task()` function releases the run queue (rq) lock, allowing an interleaving selection to invalidate the scheduler's internal state. This inc…

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.15%via CSAF
CWE-367 vulnerabilities (CVEs) · VulnSea