VulnSea

CWE-367

CVEs classified under CWE-367, newest first.

196 CVEsRSS

CVE-2026-50658High· 7.0
2mo ago

Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Microsoft Defender for Endpoint for MacEPSS 0.20%via CVEORG
CVE-2026-50673High· 7.8
2mo ago

Windows Kernel Elevation of Privilege Vulnerability

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.21%via CVEORG
CVE-2026-56178Medium· 5.5
2mo ago

Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Microsoft Defender for Endpoint for MacEPSS 0.23%via CVEORG
CVE-2026-57973Medium· 6.3
2mo ago

Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

▾ SunlitMicrosoft · Windows Subsystem for Linux (WSL2)EPSS 0.22%via CVEORG
CVE-2026-56648High· 7.5
2mo ago

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.51%via NVD
CVE-2026-45203None
2mo ago

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver c…

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver c…

▾ SunlitEPSS 0.13%via NVD
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
CVE-2026-35355Medium· 6.3
2mo ago

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

▾ Sunlituu_install · uu_installEPSS 0.11%via GHSA
CVE-2026-35356Medium· 6.3
2mo ago

install -D: symlink race in directory creation allows arbitrary file overwrite

install -D: symlink race in directory creation allows arbitrary file overwrite

▾ Sunlituu_install · uu_installEPSS 0.11%via GHSA
CVE-2026-35353Low· 3.3
2mo ago

mkdir: -m exposes directory with umask perms before chmod (race window)

mkdir: -m exposes directory with umask perms before chmod (race window)

▾ Sunlituu_mkdir · uu_mkdirEPSS 0.12%via GHSA
CVE-2026-35362Low· 3.6
2mo ago

uucore: safe_traversal TOCTOU protection only enabled on Linux

uucore: safe_traversal TOCTOU protection only enabled on Linux

▾ Sunlituucore · uucoreEPSS 0.20%via GHSA
CVE-2026-58299High· 7.5
2mo ago

Microsoft Edge for Android Remote Code Execution Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.47%via CVEORG
CVE-2026-53806High· 8.8
2mo ago

OpenClaw: Combined POSIX shell options could confuse exec revalidation

OpenClaw: Combined POSIX shell options could confuse exec revalidation

▾ Twilightopenclaw · openclawEPSS 0.61%via GHSA
GHSA-83w9-h5wv-j9xmHigh
2mo ago

OpenClaw: Node pairing reconnection could confuse approval scope state

OpenClaw: Node pairing reconnection could confuse approval scope state

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-13742Medium· 5.9
3mo ago

Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability

Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, leading to the replacement of downloade…

▾ SunlitHoneywell Technologies · IQ MultiAccessEPSS 0.11%via NVD
CVE-2026-13502Medium· 4.5
3mo ago

A flaw has been found in antlr ANTLR4 up to 4.13.2

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This m…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-54242Medium· 4.9
3mo ago

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)

▾ Sunlitstatamic · statamic/cmsEPSS 0.23%via GHSA
CVE-2026-52991High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressure write A potential race condition exists between pressure write and cgroup file release regarding the priv member …

In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressure write A potential race condition exists between pressure write and cgroup file release regarding the priv member …

▾ TwilightEPSS 0.15%via NVD
CVE-2026-48931Low· 3.7
3mo ago

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2…

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2…

▾ Sunlitnodejs · node.jsEPSS 0.37%via NVD
CVE-2026-54353High· 8.5
3mo ago

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

▾ Twilightbudibase · @budibase/backend-coreEPSS 0.21%via GHSA
CVE-2026-6733Low· 3.7
3mo ago

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

▾ Sunlitundici · undiciEPSS 0.27%via GHSA
CVE-2026-54777Medium· 6.5
3mo ago

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance

▾ SunlitCoreWCF · CoreWCF.NetNamedPipeEPSS 0.12%via GHSA
GHSA-wfqx-gjrf-g28rCritical· 9.0
3mo ago

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

Crossplane: Signature verification TOCTOU allows installing unverified package content via mutable tag

▾ Midnightcrossplane · github.com/crossplane/crossplane/v2via GHSA
GHSA-wvrh-2f4m-924vMedium· 5.5
3mo ago

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer

▾ SunlitChatterBot · ChatterBotvia GHSA
GHSA-rjvw-7vvw-549vHigh· 7.2
3mo ago

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

▾ Twilightpraisonai · praisonaivia GHSA
CVE-2026-54327Low· 2.2
3mo ago

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

▾ Sunlitmariozechner · @mariozechner/pi-coding-agentEPSS 0.09%via GHSA
CVE-2026-54228High· 7.8
3mo ago

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text…

▾ TwilightEPSS 0.13%via NVD
CVE-2026-53822High· 8.8
3mo ago

OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command sha…

▾ TwilightOpenClaw · OpenClawEPSS 2.0%via CVEORG
CVE-2026-50631High· 7.4
3mo ago

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-use semantics and generate multiple valid Access Tokens, when 'recycleRefreshTokens' is set to false. A leaked refresh…

▾ Twilightapache · cxfEPSS 0.39%via NVD
CWE-367 vulnerabilities (CVEs) — page 5 · VulnSea