The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
Volume of CVEs assigned to CWE-367 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
698 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-30088HIGH Windows Kernel Elevation of Privilege Vulnerability | Jun 11, 2024 | 7.0 | 92 | YES | NO |
CVE-2023-35311HIGH Microsoft Outlook Security Feature Bypass Vulnerability | Jul 11, 2023 | 8.8 | 73 | YES | NO |
CVE-2022-36980HIGH This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vu | Mar 29, 2023 | 8.1 | 72 | NO | NO |
CVE-2025-38352HIGH In the Linux kernel, the following vulnerability has been resolved:
posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()
If an exiting non-autor | Jul 22, 2025 | 7.4 | 70 | YES | NO |
CVE-2025-22224HIGH VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges | Mar 4, 2025 | 8.2 | 68 | YES | NO |
CVE-2023-38146HIGH Windows Themes Remote Code Execution Vulnerability | Sep 12, 2023 | 8.8 | 62 | NO | YES |
CVE-2024-0132HIGH NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container i | Sep 26, 2024 | 8.3 | 61 | NO | YES |
CVE-2022-48618HIGH The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write | Jan 9, 2024 | 7.0 | 61 | YES | NO |
CVE-2025-34027CRITICAL The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative | May 21, 2025 | 10.0 | 58 | NO | YES |
CVE-2024-50379CRITICAL Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is | Dec 17, 2024 | 9.8 | 58 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.