CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 1 of 55
- CVE-2021-21166CRITICALCVSS 8.8EG 9.0⚠ KEV2021-03-09
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-6820CRITICALCVSS 8.1EG 9.0⚠ KEV2020-04-24
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and F…
- CVE-2020-6819CRITICALCVSS 8.1EG 9.0⚠ KEV2020-04-24
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.…
- CVE-2025-43510CRITICALCVSS 7.8EG 9.0⚠ KEV2025-12-12
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1…
- CVE-2023-36884CRITICALCVSS 7.5EG 9.0⚠ KEV2023-07-11
Windows Search Remote Code Execution Vulnerability
- CVE-2025-62215CRITICALCVSS 7.0EG 9.0⚠ KEV2025-11-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2022-26904CRITICALCVSS 7.0EG 9.0⚠ KEV2022-04-15
Windows User Profile Service Elevation of Privilege Vulnerability
- CVE-2016-5195CRITICALCVSS 7.0EG 9.0⚠ KEV2016-11-10
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the…
- CVE-2021-0920CRITICALCVSS 6.4EG 9.0⚠ KEV2021-12-15
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Prod…
- CVE-2021-25395CRITICALCVSS 6.4EG 9.0⚠ KEV2021-06-11
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
- CVE-2021-25394CRITICALCVSS 6.4EG 9.0⚠ KEV2021-06-11
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
- CVE-2025-39964CRITICALCVSS 5.5EG 9.0⚠ KEV2025-10-13
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable f…
- CVE-2014-0196CRITICALCVSS 5.5EG 9.0⚠ KEV2014-05-07
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system…
- CVE-2025-66419CRITICALCVSS 10.0EG 10.02025-12-11
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in vers…
- CVE-2022-27626CRITICALCVSS 10.0EG 10.02022-10-20
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute…
- CVE-2015-8556CRITICALCVSS 10.0EG 10.02017-03-24
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
- CVE-2014-0703HIGHCVSS v2 10.0EG 10.02014-03-06
Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the administrative HTTP server, which allows remote attackers to bypass intended access restrictions by…
- CVE-2010-1228HIGHCVSS v2 10.0EG 10.02010-04-01
Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.
- CVE-2008-6598HIGHCVSS v2 10.0EG 10.02009-04-03
Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
- CVE-2002-2374HIGHCVSS v2 10.0EG 10.02002-12-31
Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."
- CVE-2024-27102CRITICALCVSS 9.9EG 9.92024-03-13
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope…
- CVE-2026-43805CRITICALCVSS 9.8EG 9.82026-07-27
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system terminat…
- CVE-2026-28982CRITICALCVSS 9.8EG 9.82026-07-27
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
- CVE-2026-64720CRITICALCVSS 9.8EG 9.82026-07-27
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
- CVE-2026-53086CRITICALCVSS 9.8EG 9.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler tries to take down all tx queues when a single queue times out. This is over zealous and causes ma…
- CVE-2026-46137CRITICALCVSS 9.8EG 9.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context. To avoid any data races, the socket…
- CVE-2026-46135CRITICALCVSS 9.8EG 9.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp),…
- CVE-2026-43198CRITICALCVSS 9.8EG 9.82026-05-06
In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock()…
- CVE-2026-5902CRITICALCVSS 9.8EG 9.82026-04-08
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-23240CRITICALCVSS 9.8EG 9.82026-03-10
In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After cancel_delayed_work_sync() is called from tls_sk_proto_close(), …
- CVE-2025-43275CRITICALCVSS 9.8EG 9.82025-07-30
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
- CVE-2025-43244CRITICALCVSS 9.8EG 9.82025-07-30
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.
- CVE-2025-30444CRITICALCVSS 9.8EG 9.82025-03-31
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Mounting a maliciously crafted SMB network share may lead to system termination.
- CVE-2024-48069CRITICALCVSS 9.8EG 9.82024-11-19
A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges
- CVE-2023-32254CRITICALCVSS 9.8EG 9.82023-07-10
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing opera…
- CVE-2023-28201CRITICALCVSS 9.8EG 9.82023-05-08
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app terminati…
- CVE-2022-44551CRITICALCVSS 9.8EG 9.82022-11-09
The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.
- CVE-2022-39328CRITICALCVSS 9.8EG 9.82022-11-08
Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an admi…
- CVE-2021-32810CRITICALCVSS 9.8EG 9.82021-08-02
crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped …
- CVE-2021-26569CRITICALCVSS 9.8EG 9.82021-03-12
Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.
- CVE-2020-35879CRITICALCVSS 9.8EG 9.82020-12-31
An issue was discovered in the rulinalg crate through 2020-02-11 for Rust. There are incorrect lifetime-boundary definitions for RowMut::raw_slice and RowMut::raw_slice_mut.
- CVE-2020-10279CRITICALCVSS 9.8EG 9.82020-06-24
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate…
- CVE-2019-2006CRITICALCVSS 9.8EG 9.82019-06-19
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction…
- CVE-2019-12450CRITICALCVSS 9.8EG 9.82019-05-29
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
- CVE-2015-9157CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 600, SD 615/16/SD 415, SD 61…
- CVE-2016-0930CRITICALCVSS 9.8EG 9.82016-09-18
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installat…
- CVE-2026-56188CRITICALCVSS 8.1EG 9.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
- CVE-2023-27359CRITICALCVSS 8.1EG 9.82024-05-03
TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to …
- CVE-2021-41025CRITICALCVSS 7.3EG 9.82021-12-08
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using s…
- CVE-2021-39713CRITICALCVSS 7.0EG 9.82022-03-16
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →