Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

699 CVEs tagged with CWE-36727 Critical, 354 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2026-62428

Published Jul 28, 2026

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For all copy operations the refer…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-59676

Published Jul 23, 2026

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-65598

Published Jul 22, 2026

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping…

CVSS 8.9 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-16082

Published Jul 18, 2026

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-54242

Published Jul 17, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php an…

CVSS 4.9 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-62212

Published Jul 17, 2026

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or conf…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53410

Published Jul 16, 2026

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user t…

CVSS 7.0 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-15449

Published Jul 16, 2026

A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_i…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-45804

Published Jul 15, 2026

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because downl…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-57973

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-56648

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-56178

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-50658

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-4018

Published Jul 14, 2026

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause informa…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62189

Published Jul 13, 2026

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger author…

CVSS 7.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-45203

Published Jul 10, 2026

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56676

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the l…

CVSS 7.4 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-58198

Published Jul 9, 2026

ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directo…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2025-58151

Published Jul 9, 2026

varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF.…

CVSS 9.4 · Critical

CVE-2026-54777

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts attachment to a pre-…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-43927

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an authenticated client to apply…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 699 CVEsPage 1 of 28