Skip to main content

CWE archive

CWE-367 CVEs

Programmatic archive

699 CVEs tagged with CWE-36727 Critical, 354 High, 271 Medium, 47 Low, 0 Unrated.

CVE-2024-34528

Published May 6, 2024

WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.

CVSS 7.7 · High

CVE-2023-32156

Published May 3, 2024

Tesla Model 3 Gateway Firmware Signature Validation Bypass Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Tesla Model 3…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27327

Published May 3, 2024

Parallels Desktop Toolgate Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected install…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27323

Published May 3, 2024

Parallels Desktop Updater Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23463

Published Apr 30, 2024

Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48682

Published Apr 26, 2024

In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.

CVSS 6.0 · Medium

CVE-2024-32482

Published Apr 23, 2024

The Tillitis TKey signer device application is an ed25519 signing tool. A vulnerability has been found that makes it possible to disclose portions of the TKey’s data in RAM over t…

CVSS 2.2 · Low

CVE-2024-2440

Published Apr 19, 2024

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter repository permission…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24995

Published Apr 19, 2024

A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24993

Published Apr 19, 2024

A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28718

Published Apr 12, 2024

An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1729

Published Mar 29, 2024

A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability arises from the use of a direct co…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28183

Published Mar 25, 2024

ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-of-Use (TOCTOU) vulnerability was discovered in the implemen…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33632

Published Mar 25, 2024

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnera…

CVSS 7.0 · High

CVE-2023-32282

Published Mar 14, 2024

Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVSS 7.2 · High

CVE-2024-24692

Published Mar 13, 2024

Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of service via local access.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27297

Published Mar 11, 2024

Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors to files in the Nix store to another program running on th…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52556

Published Mar 1, 2024

In OpenBSD 7.4 before errata 009, a race condition between pf(4)'s processing of packets and expiration of packet states may cause a kernel panic.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 699 CVEsPage 16 of 28