VulnSea

CWE-367

CVEs classified under CWE-367, newest first.

196 CVEsRSS

CVE-2026-87523Medium· 5.3⚖ disputed
2w ago

Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page

Race condition in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-28671Low· 3.3
2w ago

In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition

In updateInternal of MediaProvider.java, there is a possible expose contents of files due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

▾ Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-78464High· 7.0
2w ago

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.20%via NVD
CVE-2026-69859High· 7.0
2w ago

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows USB Audio Class driver (usbaudio.sys) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-69804High· 7.5
2w ago

Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · sharepoint_serverEPSS 0.51%via NVD
CVE-2026-69779High· 7.0
2w ago

Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-69563High· 7.0
2w ago

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-69466High· 7.0
2w ago

Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-69440High· 7.0
2w ago

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.21%via NVD
CVE-2026-12611High· 8.7
2w ago

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole server to become unresponsive. This is caused by a race conditio…

▾ TwilightEclipse Foundation · Eclipse JettyEPSS 0.25%via NVD
CVE-2026-86424Low· 2.5
2w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlin…

▾ Sunlitimagemagick · imagemagickEPSS 0.14%via NVD
CVE-2026-86422Low· 3.3
2w ago

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap sym…

▾ Sunlitimagemagick · imagemagickEPSS 0.13%via NVD
CVE-2026-76925Medium· 5.8
3w ago

A flaw was found in Flatpak

A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTr…

▾ SunlitRed Hat · flatpakEPSS 0.10%via NVD
CVE-2026-18567Medium· 4.4
3w ago

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.

▾ Sunlitibm · db2_mirror_for_iEPSS 0.07%via NVD
CVE-2026-45197Low· 2.5
3w ago

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory. The firmware uses data provided by the Guest VM to …

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory. The firmware uses data provided by the Guest VM to …

▾ SunlitImagination Technologies · Graphics DDKEPSS 0.09%via NVD
CVE-2026-85045High· 7.5PoC
3w ago

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.29%via NVD
CVE-2026-80047High· 7.8
3w ago

A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate()

A vulnerability in Hugging Face Transformers (versions 4.57.0 to 5.16.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and ca…

▾ TwilightHugging Face · TransformersEPSS 0.10%via NVD
CVE-2026-19118High· 7.5
3w ago

A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution

A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of c…

▾ Twilightgithub · enterprise_serverEPSS 0.54%via NVD
CVE-2026-82238Low· 3.1
1mo ago

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous P…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-54754Critical· 9.6
1mo ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPer…

▾ Midnightklever-io · github.com/klever-io/klever-goEPSS 0.43%via NVD
GHSA-mf7q-r4rv-jv94High
1mo ago

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature…

Crossplane's TOCTOU between cosign verification and image fetch in xpkg.CachedClient allows tag-based package install to bypass signature check

▾ Twilightcrossplane · github.com/crossplane/crossplane-runtime/v2via OSV
CVE-2026-58094High· 7.8
1mo ago

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked w…

▾ Twilightfreebsd · freebsdEPSS 0.12%via NVD
CVE-2026-80521High· 7.8PoC
1mo ago

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: …

In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle Zeng reported that GC could free a dead SCC partially. The scenario is as follows: 1) Create two SCCs: …

▾ MidnightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-77573Low· 3.5
1mo ago

Weblate is a web-based continuous localization platform used to manage software translations

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal serv…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-47836High· 7.2
1mo ago

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud …

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud …

▾ Twilightvmware · spring_cloud_configEPSS 0.22%via NVD
CVE-2026-79089Medium· 5.3
1mo ago

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severi…

▾ SunlitGoogle · ChromeEPSS 0.21%via CVEORG
CVE-2026-55537High· 7.1
1mo ago

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

▾ Twilightpraisonai · praisonaiEPSS 0.27%via OSV
CVE-2026-55535Medium· 6.8
1mo ago

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

▾ Sunlitpraisonai · praisonaiEPSS 0.34%via OSV
CVE-2026-49114High· 7.1
1mo ago

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. …

▾ Twilightlinuxfoundation · onnxEPSS 0.16%via NVD
CVE-2026-64846Low· 2.8
1mo ago

Nix is a package manager for Linux and other Unix systems

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.11%via NVD
CWE-367 vulnerabilities (CVEs) — page 3 · VulnSea