CWE-367
CVEs classified under CWE-367, newest first.
196 CVEsRSS
CVE-2026-50658High· 7.0Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVE-2026-50673High· 7.8Windows Kernel Elevation of Privilege Vulnerability
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-56178Medium· 5.5Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
CVE-2026-57973Medium· 6.3Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
CVE-2026-56648High· 7.5Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.
CVE-2026-45203NoneKernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver c…
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver c…
CVE-2026-53517High· 8.1Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption
CVE-2026-53518High· 8.1@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive
CVE-2026-35355Medium· 6.3install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite
CVE-2026-35356Medium· 6.3install -D: symlink race in directory creation allows arbitrary file overwrite
install -D: symlink race in directory creation allows arbitrary file overwrite
CVE-2026-35353Low· 3.3mkdir: -m exposes directory with umask perms before chmod (race window)
mkdir: -m exposes directory with umask perms before chmod (race window)
CVE-2026-35362Low· 3.6uucore: safe_traversal TOCTOU protection only enabled on Linux
uucore: safe_traversal TOCTOU protection only enabled on Linux
CVE-2026-58299High· 7.5Microsoft Edge for Android Remote Code Execution Vulnerability
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
CVE-2026-53806High· 8.8OpenClaw: Combined POSIX shell options could confuse exec revalidation
OpenClaw: Combined POSIX shell options could confuse exec revalidation
GHSA-83w9-h5wv-j9xmHighOpenClaw: Node pairing reconnection could confuse approval scope state
OpenClaw: Node pairing reconnection could confuse approval scope state
CVE-2026-13742Medium· 5.9Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability
Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, leading to the replacement of downloade…
CVE-2026-13502Medium· 4.5A flaw has been found in antlr ANTLR4 up to 4.13.2
A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This m…
CVE-2026-54242Medium· 4.9Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-52991High· 7.8In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressure write A potential race condition exists between pressure write and cgroup file release regarding the priv member …
In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressure write A potential race condition exists between pressure write and cgroup file release regarding the priv member …
CVE-2026-48931Low· 3.7A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2…
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2…
CVE-2026-54353High· 8.5@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
CVE-2026-6733Low· 3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-54777Medium· 6.5CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance
GHSA-wfqx-gjrf-g28rCritical· 9.0Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag
GHSA-wvrh-2f4m-924vMedium· 5.5ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
GHSA-rjvw-7vvw-549vHigh· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
CVE-2026-54327Low· 2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
CVE-2026-54228High· 7.8A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text…
CVE-2026-53822High· 8.8OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution
OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command sha…
CVE-2026-50631High· 7.4A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh…