Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

698 CVEs tagged with CWE-36727 Critical, 353 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2025-21746

Published Feb 27, 2025

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics - fix crash when enabling pass-through port When enabling a pass-through port an interrupt m…

CVSS 4.7 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-26620

Published Feb 18, 2025

Duende.AccessTokenManagement is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. Duende.AccessTokenManagement contains a race condition when requesting…

CVSS 6.3 · Medium

CVE-2024-41917

Published Feb 12, 2025

Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 may allow an authenticated user to potentially enable escalat…

CVSS 5.4 · Medium

CVE-2024-48394

Published Feb 5, 2025

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and…

CVSS 7.8 · High

CVE-2024-37181

Published Jan 16, 2025

Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosu…

CVSS 2.1 · Low

CVE-2025-22394

Published Jan 15, 2025

Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could pote…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42444

Published Jan 14, 2025

APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful exploitation of this vulnerability may lead to execution of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41787

Published Jan 10, 2025

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a speciall…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-10972

Published Dec 16, 2024

Velocidex WinPmem versions 4.1 and below suffer from an Improper Input Validation vulnerability whereby an attacker with admin access can trigger a BSOD with a parallel thread cha…

CVSS 7.3 · High

CVE-2024-53289

Published Dec 11, 2024

Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27134

Published Nov 25, 2024

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-41779

Published Nov 22, 2024

IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a spe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-22185

Published Nov 13, 2024

Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS 8.5 · High

CVE-2024-51563

Published Nov 12, 2024

The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.

CVSS 6.5 · Medium

CVE-2024-48322

Published Nov 11, 2024

UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.

CVSS 8.1 · High
Showing 301-325 of 698 CVEsPage 13 of 28