VulnSea

CWE-367

CVEs classified under CWE-367, newest first.

196 CVEsRSS

CVE-2026-42306High· 7.2
3mo ago

github.com/docker/docker: github.com/moby/moby: Moby container framework: Host file overwrite via race condition in docker cp mount setup (…

A flaw was found in the Moby container framework. A race condition occurs during the `docker cp` mount setup, which a malicious container can exploit. This vulnerability allows the container to redirect a bind mount target to an arbitrary …

▾ TwilightRed Hat · Red Hat Edge Manager 1.1EPSS 0.10%via CSAF
GHSA-9wcp-79g5-5c3cHigh· 8.1
3mo ago

Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators

Appsmith Super User Creation Race Condition Allows Multiple Instance Administrators

▾ Twilightappsmith · com.appsmith:servervia GHSA
CVE-2026-54096High
3mo ago

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path

▾ Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.18%via GHSA
CVE-2026-45487High· 7.8
3mo ago

Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability

Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.21%via CVEORG
CVE-2026-45647Medium· 5.5
3mo ago

Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

▾ SunlitMicrosoft · Microsoft Defender for Endpoint for MacEPSS 0.23%via CVEORG
CVE-2026-9796Medium· 6.5
4mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their…

▾ Sunlitredhat · build_of_keycloakEPSS 0.38%via NVD
CVE-2026-46227High· 7.8
4mo ago

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), w…

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL The SCTP_SENDALL path in sctp_sendmsg() iterates ep->asocs with list_for_each_entry_safe(), w…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-29518High· 7.0
4mo ago

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with s…

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with s…

▾ Twilightsamba · rsyncEPSS 0.14%via NVD
CVE-2026-5947High· 7.5
4mo ago

Undefined behavior may result due to a race condition leading to a use-after-free violation

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recur…

▾ Twilightisc · bindEPSS 0.80%via NVD
CVE-2026-44113High· 7.7
4mo ago

OpenClaw < 2026.4.22 - Time-of-Check/Time-of-Use Race Condition in OpenShell FS Bridge

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem o…

▾ TwilightOpenClaw · OpenClawEPSS 0.34%via CVEORG
CVE-2026-44112Critical· 9.6
4mo ago

OpenClaw < 2026.4.22 - Symlink Swap Race Condition in OpenShell FS Bridge Writes

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during fil…

▾ MidnightOpenClaw · OpenClawEPSS 0.39%via CVEORG
CVE-2026-1880Medium· 5.4PoC
5mo ago

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources during the validation phase, permitting a …

▾ TwilightASUS · DriverHubEPSS 0.14%via NVD
CVE-2026-27929High· 7.0
5mo ago

Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-32093High· 7.0
5mo ago

Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-4878Medium· 6.7
5mo ago

A flaw was found in libcap

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file c…

▾ Sunlitlibcap_project · libcapEPSS 0.14%via NVD
CVE-2026-32282High· 7.8
5mo ago

golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)

A flaw was found in the internal/syscall/unix package in the Go standard library. If the target of the `Root.Chmod` function is replaced with a symbolic link during execution, specifically after `Root.Chmod` checks the target but before ac…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.17%via CSAF
CVE-2026-35554High· 8.7
5mo ago

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containi…

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containi…

▾ Twilightapache · kafkaEPSS 0.65%via NVD
CVE-2026-27456Medium· 4.7
5mo ago

util-linux is a random collection of Linux utilities

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up lo…

▾ Sunlitkernel · util-linuxEPSS 0.12%via NVD
CVE-2026-32988High· 7.5
6mo ago

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in p…

▾ Twilightopenclaw · openclawEPSS 0.11%via NVD
CVE-2026-32977Medium· 6.3
6mo ago

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that uses an unanchored container path during the final move operation. An attacker can exploit a time-of-check-time-of-use…

▾ Sunlitopenclaw · openclawEPSS 0.11%via NVD
CVE-2026-32921Medium· 6.3
6mo ago

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not bound across approval and execution phases. Attackers can obtain approval for script execution, modify the approved sc…

▾ Sunlitopenclaw · openclawEPSS 0.33%via NVD
CVE-2026-34224Medium· 4.4
6mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery…

▾ Sunlitparseplatform · parse-serverEPSS 0.34%via NVD
CVE-2026-26017High· 7.7
6mo ago

CoreDNS is a DNS server that chains plugins

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated …

▾ Twilightcoredns.io · corednsEPSS 0.46%via NVD
CVE-2026-20677Critical· 9.0
7mo ago

A race condition was addressed with improved handling of symbolic links

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcu…

▾ Midnightapple · ipadosEPSS 0.29%via NVD
CVE-2025-13818Medium· 6.7
7mo ago

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

▾ Sunliteset · management_agentEPSS 0.13%via NVD
CVE-2026-25536High· 7.1
7mo ago

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multi…

▾ Twilightlfprojects · mcp_typescript_sdkEPSS 0.36%via NVD
CVE-2026-23950High· 8.8
8mo ago

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalizatio…

▾ Twilightisaacs · tarEPSS 0.26%via NVD
CVE-2026-20831High· 7.8
8mo ago

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.30%via NVD
CVE-2026-20816High· 7.8
8mo ago

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 2.5%via NVD
CVE-2026-20809High· 7.8
8mo ago

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.36%via NVD
CWE-367 vulnerabilities (CVEs) — page 6 · VulnSea