Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-367

MITRE ↗

CWE-367

32
CRITICAL
378
HIGH
280
MEDIUM
46
LOW
770 CVEs · Page 3/16
7.2
CVE-2026-41002

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi

7.2
CVE-2026-42306

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and

7.1
CVE-2026-25536

MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to

7.1
CVE-2026-62189

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower

7.1
CVE-2026-62212

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea

7.1
CVE-2026-64284

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs before

7.1
CVE-2026-16896

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to obtain unauthorized access to files due to a

7.1
CVE-2026-49114

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_da

7.1
CVE-2026-55537

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webh

7.0
CVE-2026-0924

BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root

7.0
CVE-2026-27929

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges l

7.0
CVE-2026-32093

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic

7.0
CVE-2026-35352

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre

7.0
CVE-2026-34596

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of

7.0
CVE-2026-29518

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that

7.0
CVE-2025-71215

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c

7.0
CVE-2026-50658

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile

7.0
CVE-2026-53410

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl

7.0
CVE-2026-62728

Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker

7.0
CVE-2026-16838

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite critical files and obtain sensit

7.0
CVE-2026-16922

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-ch

6.8
CVE-2025-67124

A TOCTOU and symlink race in svenstaro/miniserve 0.32.0 upload finalization (when uploads are enabled) can allow an atta

6.8
CVE-2026-55535

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open

6.7
CVE-2025-47332

Memory corruption while processing a config call from userspace.

6.7
CVE-2025-47344

Memory corruption while handling sensor utility operations.

6.7
CVE-2025-13818

Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent

6.7
CVE-2026-4878

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition

6.7
CVE-2026-41360

OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan

6.6
CVE-2026-27189

OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-a

6.5
CVE-2026-32043

OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run exec

6.5
CVE-2026-3590

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin

6.5
CVE-2026-40896

OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`

6.5
CVE-2026-26206

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo

6.5
CVE-2025-69233

Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as mi

6.5
CVE-2026-9796

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check

6.5
CVE-2026-45619

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o

6.5
CVE-2026-54777

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,

6.5
CVE-2026-13113

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2

6.5
CVE-2026-66314

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to

6.5
CVE-2026-47621

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing

6.5
CVE-2026-79017

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access r

6.4
CVE-2026-20438

In MAE, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privileg

6.4
CVE-2026-20454

In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of pr

6.4
CVE-2025-59610

Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-spa

6.4
CVE-2026-4018

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local acce

6.4
CVE-2026-9728

The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->si

6.3
CVE-2026-27127

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF

6.3
CVE-2026-28689

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1

6.3
CVE-2026-32921

OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b

6.3
CVE-2026-32977

OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u

Frequently Asked Questions

What is CWE-367?

CWE-367 (CWE-367) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-367?

There are 938 CVE records associated with CWE-367 in our database. Of these, 32 are critical severity, 378 are high severity, and 280 are medium severity.

How can I protect against CWE-367 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-367 using AI-powered security agents.

Detect CWE-367 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-367 vulnerabilities across your infrastructure.

Get Started