Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

703 CVEs tagged with CWE-36727 Critical, 358 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2026-67433

Published Jul 29, 2026

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-13113

Published Jul 29, 2026

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have all…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-56822

Published Jul 29, 2026

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshak…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-55391

Published Jul 28, 2026

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. P…

CVSS 7.5 · High
evidence mentions
4
Buzz score
22.6

CVE-2026-62428

Published Jul 28, 2026

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a mapping or another copy). For all copy operations the refer…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-59676

Published Jul 23, 2026

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-65598

Published Jul 22, 2026

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping…

CVSS 8.9 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-16082

Published Jul 18, 2026

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation…

CVSS 1.9 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-54242

Published Jul 17, 2026

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php an…

CVSS 4.9 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-62212

Published Jul 17, 2026

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller or conf…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-53410

Published Jul 16, 2026

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user t…

CVSS 7.0 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-15449

Published Jul 16, 2026

A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC_GETMACPROP and DLDIOC_SETMACPROP ioctls on /dev/dld. drv_i…

CVSS 5.8 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-45804

Published Jul 15, 2026

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretrained flow can bypass the trust_remote_code guard because downl…

CVSS 7.5 · High
evidence mentions
5
Buzz score
22.9

CVE-2026-57973

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.

CVSS 6.3 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-56648

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1

CVE-2026-56178

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-50658

Published Jul 14, 2026

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-4018

Published Jul 14, 2026

TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause informa…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62189

Published Jul 13, 2026

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger author…

CVSS 7.6 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-45203

Published Jul 10, 2026

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-56676

Published Jul 10, 2026

9Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetching, but open-sse/translator/concerns/image.js performs the l…

CVSS 7.4 · High
evidence mentions
3
Buzz score
18.9
Showing 1-25 of 703 CVEsPage 1 of 29