VulnSea

CWE-367

CVEs classified under CWE-367, newest first.

196 CVEsRSS

CVE-2026-16935High· 7.8
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.

▾ TwilightEPSS 0.07%via NVD
CVE-2026-76020High· 7.5
1mo ago

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ TwilightEPSS 0.29%via NVD
CVE-2026-73829Low· 3.7
1mo ago

Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.…

Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for multiple paid-resource accesses. The type="hash" credential path in MPP.Methods.Tempo.…

▾ Sunlitzenhive · machine_payments_protocolEPSS 0.32%via NVD
CVE-2026-16838High· 7.0
1mo ago

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensitive information due to a time-of-check to time-of-use (TOCTOU) race condition.

▾ TwilightEPSS 0.10%via NVD
CVE-2026-71539None
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted …

▾ SunlitEPSS 0.30%via NVD
CVE-2026-70667Medium· 6.3
1mo ago

Lemur manages TLS certificate creation

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL but the later request could reach a different destination. The CRL requests.get call fo…

▾ Sunlitlemur · lemurEPSS 0.18%via NVD
CVE-2026-73410High· 8.5
1mo ago

Budibase is an open-source low-code platform

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/u…

▾ TwilightEPSS 0.28%via NVD
CVE-2026-53796Medium· 6.3
1mo ago

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to…

rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the non-daemon receiver's destination directory handling that allows an attacker who can manipulate destination path parent components to…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-63297Critical· 9.9PoC
1mo ago

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a tar…

▾ Abyssalcanonical · lxdEPSS 0.34%via NVD
CVE-2026-49262Low· 3.0
1mo ago

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding

In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) …

▾ Sunlitaimeos · aimeos/pagibleEPSS 0.17%via NVD
CVE-2026-62728High· 7.0
1mo ago

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-72584High· 7.4
1mo ago

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brute-force attacks on 6-digit OTP codes.

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brute-force attacks on 6-digit OTP codes.

▾ TwilightEPSS 0.39%via NVD
CVE-2026-43632High· 8.1
1mo ago

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that by…

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokenize, /detokenize, /infill, /apply-template, /rerank, and /anthropic/count_tokens) that by…

▾ Twilightggml · llama.cppEPSS 0.48%via NVD
CVE-2026-55524High· 7.5
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, allowing the protection to be bypassed so the tool connects to attacker-chosen internal …

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.24%via NVD
CVE-2026-71210Medium· 5.3
1mo ago

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname,…

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request using the original hostname,…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-70597Medium· 6.3
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the check Electron uses on macOS to confirm it was launched by a same-signed pare…

▾ Sunlitelectron · electronEPSS 0.11%via NVD
CVE-2026-53945Medium· 4.0
1mo ago

Ghost: Server-side request forgery via DNS rebinding in external request handling

Ghost: Server-side request forgery via DNS rebinding in external request handling

▾ Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-54020Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients re…

▾ Sunlitopenwebui · open_webuiEPSS 0.25%via NVD
CVE-2026-18477Medium· 4.4
1mo ago

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access …

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access …

▾ Sunlitgnu · tarEPSS 0.08%via NVD
CVE-2026-47746None
1mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks during JSON-LD signature validation and the compaction process. Because the JSON-LD parsing c…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-66314Medium· 6.5
1mo ago

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.57%via CVEORG
CVE-2026-20474None
1mo ago

In display, there is a possible escalation of privilege due to a race condition

In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploita…

▾ SunlitEPSS 0.13%via NVD
CVE-2026-67607Medium· 5.9PoC
1mo ago

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon b…

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon b…

▾ Twilighthfiref0x · LightFTPEPSS 0.40%via NVD
CVE-2026-55391High· 7.5
2mo ago

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.30%via OSV
GHSA-v42f-v8xc-j435High· 8.5
2mo ago

Budibase: SSRF via DNS rebinding in the REST datasource integration

Budibase: SSRF via DNS rebinding in the REST datasource integration

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-56m6-8q75-f2rwMedium· 4.7
2mo ago

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

ImageMagick: Policy Bypass due to an incomplete fix of CVE-2026-49219

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2026-56822High· 7.4
2mo ago

Netty: TOCTOU in OcspServerCertificateValidator

Netty: TOCTOU in OcspServerCertificateValidator

▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.17%via GHSA
GHSA-725q-c4vp-q4cgHigh
2mo ago

Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

▾ Twilightn8n · n8nvia GHSA
CVE-2026-65598High
2mo ago

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

▾ Twilightn8n · n8nEPSS 0.34%via GHSA
CVE-2026-16082Medium· 5.3
2mo ago

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. T…

▾ SunlitEPSS 0.12%via NVD
CWE-367 vulnerabilities (CVEs) — page 4 · VulnSea