Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-367

MITRE ↗

CWE-367

32
CRITICAL
378
HIGH
280
MEDIUM
46
LOW
770 CVEs · Page 2/16
7.8
CVE-2022-26522

The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local

7.8
CVE-2026-43433

In the Linux kernel, the following vulnerability has been resolved: rust_binder: avoid reading the written value in off

7.8
CVE-2026-35418

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-41702

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a

7.8
CVE-2025-71216

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local at

7.8
CVE-2026-45208

A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges

7.8
CVE-2026-24191

NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use iss

7.8
CVE-2026-46227

In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_

7.8
CVE-2026-25260

Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.

7.8
CVE-2026-45487

Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack

7.8
CVE-2026-54228

A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee

7.8
CVE-2026-52991

In the Linux kernel, the following vulnerability has been resolved: sched/psi: fix race between file release and pressu

7.8
CVE-2026-53145

In the Linux kernel, the following vulnerability has been resolved: drm/gem: Try to fix change_handle ioctl, attempt 4

7.8
CVE-2026-53250

In the Linux kernel, the following vulnerability has been resolved: xsk: cache csum_start/csum_offset to fix TOCTOU in

7.8
CVE-2026-25271

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec

7.8
CVE-2026-45203

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor

7.8
CVE-2026-50673

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-48344

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul

7.8
CVE-2026-64112

In the Linux kernel, the following vulnerability has been resolved: rbd: eliminate a race in lock_dwork draining on unm

7.8
CVE-2026-62428

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a

7.8
CVE-2026-12234

The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn

7.8
CVE-2026-53477

Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab

7.8
CVE-2026-16935

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-

7.8
CVE-2026-58094

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to

7.7
CVE-2026-26017

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce

7.7
CVE-2026-44113

OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al

7.7
CVE-2026-16819

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise d

7.6
CVE-2024-13942

Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external me

7.5
CVE-2026-25728

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) ra

7.5
CVE-2026-32988

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi

7.5
CVE-2026-30332

A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows

7.5
CVE-2026-5947

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi

7.5
CVE-2026-58299

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu

7.5
CVE-2026-56648

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevat

7.5
CVE-2026-45804

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine

7.5
CVE-2026-65598

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a

7.5
CVE-2026-55391

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch

7.5
CVE-2026-55524

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on

7.5
CVE-2026-76020

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside

7.4
CVE-2026-34354

Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escal

7.4
CVE-2025-64390

A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Di

7.4
CVE-2026-50631

A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u

7.4
CVE-2026-56676

9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetchin

7.4
CVE-2026-56822

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,

7.4
CVE-2026-72584

A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac

7.3
CVE-2026-23988

Rufus is a utility that helps format and create bootable USB flash drives. Versions 4.11 and below contain a race condit

7.3
CVE-2026-2364

If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr

7.3
CVE-2026-32979

OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local cod

7.3
CVE-2026-56797

Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A

7.3
CVE-2026-16927

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-chec

Frequently Asked Questions

What is CWE-367?

CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-367?

There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.

How can I protect against CWE-367 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.

Detect CWE-367 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.

Get Started