The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower
OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs before
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_da
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webh
BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root
Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges l
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile
A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensit
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-ch
A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open
Memory corruption while processing a config call from userspace.
Memory corruption while handling sensor utility operations.
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-a
OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run exec
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin
OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check
WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2
Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing
Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access r
In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privileg
In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of pr
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa
TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local acce
The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->si
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u
Frequently Asked Questions
What is CWE-367?
CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-367?
There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.
How can I protect against CWE-367 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.
Detect CWE-367 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.
Get Started