Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

698
Assigned CVEs
60th
Commonality Rank
6.5
Avg CVSS
0.7%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-367 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2003
22 years ago
Most Recent CVE
Jul 23, 2026
0 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

698 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-30088HIGH
Windows Kernel Elevation of Privilege Vulnerability
Jun 11, 20247.092YESNO
CVE-2023-35311HIGH
Microsoft Outlook Security Feature Bypass Vulnerability
Jul 11, 20238.873YESNO
CVE-2022-36980HIGH
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vu
Mar 29, 20238.172NONO
CVE-2025-38352HIGH
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autor
Jul 22, 20257.470YESNO
CVE-2025-22224HIGH
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges
Mar 4, 20258.268YESNO
CVE-2023-38146HIGH
Windows Themes Remote Code Execution Vulnerability
Sep 12, 20238.862NOYES
CVE-2024-0132HIGH
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container i
Sep 26, 20248.361NOYES
CVE-2022-48618HIGH
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write
Jan 9, 20247.061YESNO
CVE-2025-34027CRITICAL
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative
May 21, 202510.058NOYES
CVE-2024-50379CRITICAL
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is
Dec 17, 20249.858NONO
View all 698 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
11%
10%
4.0-4.9
12%
19%
5.0-5.9
16%
16%
6.0-6.9
45%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
0.7% of CVEs· 88th percentile
Metasploit
2 CVEs
0.3% of CVEs· 81st percentile
Nuclei
2 CVEs
0.3% of CVEs· 79th percentile
ExploitDB
13 CVEs
1.9% of CVEs· 87th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products