CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 14 of 55
- CVE-2025-55231HIGHCVSS 7.5EG 7.52025-08-21
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
- CVE-2025-50169HIGHCVSS 7.5EG 7.52025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.
- CVE-2025-52434HIGHCVSS 7.5EG 7.52025-07-10
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connect…
- CVE-2025-46613HIGHCVSS 7.5EG 7.52025-04-25
OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable.
- CVE-2023-49603HIGHCVSS 7.5EG 7.52025-02-12
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-11144HIGHCVSS 7.5EG 7.52024-12-16
The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfe…
- CVE-2024-49129HIGHCVSS 7.5EG 7.52024-12-12
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
- CVE-2024-49353HIGHCVSS 7.5EG 7.52024-11-26
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.
- CVE-2023-41833HIGHCVSS 7.5EG 7.52024-09-16
A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2024-43467HIGHCVSS 7.5EG 7.52024-09-10
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- CVE-2024-45300HIGHCVSS 7.5EG 7.52024-09-06
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user to bypass the limit on the number of promo codes and use the discount coupon…
- CVE-2024-7885HIGHCVSS 7.5EG 7.52024-08-21
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP …
- CVE-2024-40815HIGHCVSS 7.5EG 7.52024-07-29
A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may…
- CVE-2024-20007HIGHCVSS 7.5EG 7.52024-02-05
In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS0…
- CVE-2023-6200HIGHCVSS 7.5EG 7.52024-01-28
A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent network could send an ICMPv6 router advertisement packet, causing arbitrary code execution.
- CVE-2024-0605HIGHCVSS 7.5EG 7.52024-01-22
Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions …
- CVE-2024-21307HIGHCVSS 7.5EG 7.52024-01-09
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2024-20700HIGHCVSS 7.5EG 7.52024-01-09
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2023-34438HIGHCVSS 7.5EG 7.52023-08-11
Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2023-35309HIGHCVSS 7.5EG 7.52023-07-11
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-29537HIGHCVSS 7.5EG 7.52023-06-02
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
- CVE-2023-33974HIGHCVSS 7.5EG 7.52023-05-30
RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In versions 2023.01 and prior, an attacker can send multiple crafted frames to the device to trigger a …
- CVE-2023-1285HIGHCVSS 7.5EG 7.52023-04-14
Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in E…
- CVE-2023-28232HIGHCVSS 7.5EG 7.52023-04-11
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2022-48221HIGHCVSS 7.5EG 7.52023-04-04
An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. Multiple MSI's get executed out of a standard-user writable directory. Through a race condition and OpLock manipulation, these files can be overwritten by a standard user. T…
- CVE-2022-32764HIGHCVSS 7.5EG 7.52023-02-16
Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-24042HIGHCVSS 7.5EG 7.52023-01-21
A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.
- CVE-2023-22499HIGHCVSS 7.5EG 7.52023-01-17
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to …
- CVE-2022-22737HIGHCVSS 7.5EG 7.52022-12-22
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Fir…
- CVE-2022-41118HIGHCVSS 7.5EG 7.52022-11-09
Windows Scripting Languages Remote Code Execution Vulnerability
- CVE-2016-20015HIGHCVSS 7.5EG 7.52022-09-20
In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to gain ownership of any file, allowing for the smokeping user to gain root privileges. There is a race condition involving …
- CVE-2022-24950HIGHCVSS 7.5EG 7.52022-08-16
A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other users' SSH authorization socket, enabling the attacker to login to other systems as the targeted users. The bug is in …
- CVE-2022-24949HIGHCVSS 7.5EG 7.52022-08-16
A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a race condition, buffer overflow, and logic bug all in PipeSocketHandler::listen().
- CVE-2022-35796HIGHCVSS 7.5EG 7.52022-08-09
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- CVE-2022-26701HIGHCVSS 7.5EG 7.52022-05-26
A race condition was addressed with improved locking. This issue is fixed in tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. An application may be able to execute arbitrary code with kernel privileges.
- CVE-2021-43411HIGHCVSS 7.5EG 7.52021-11-07
An issue was discovered in GNU Hurd before 0.9 20210404-9. When trying to exec a setuid executable, there's a window of time when the process already has the new privileges, but still refers to the old task and is accessible through the ol…
- CVE-2021-37991HIGHCVSS 7.5EG 7.52021-11-02
Race in V8 in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-29622HIGHCVSS 7.5EG 7.52021-10-19
A race condition was addressed with additional validation. This issue is fixed in Security Update 2021-005 Catalina. Mounting a maliciously crafted NFS network share may lead to arbitrary code execution with system privileges.
- CVE-2021-30603HIGHCVSS 7.5EG 7.52021-08-26
Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-30984HIGHCVSS 7.5EG 7.52021-08-24
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code e…
- CVE-2021-38587HIGHCVSS 7.5EG 7.52021-08-11
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
- CVE-2021-21005HIGHCVSS 7.5EG 7.52021-06-25
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted a…
- CVE-2021-29952HIGHCVSS 7.5EG 7.52021-06-24
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Fire…
- CVE-2021-20181HIGHCVSS 7.5EG 7.52021-05-13
A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a malicious 9p client to cause a use-after-free error, potentially escalating their privileges on the system. The highest…
- CVE-2021-0270HIGHCVSS 7.5EG 7.52021-04-22
On PTX Series and QFX10k Series devices with the "inline-jflow" feature enabled, a use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Juniper Networks Junos OS may allow an attacker to cause a Denial …
- CVE-2020-25584HIGHCVSS 7.5EG 7.52021-04-07
In FreeBSD 13.0-STABLE before n245118, 12.2-STABLE before r369552, 11.4-STABLE before r369560, 13.0-RC5 before p1, 12.2-RELEASE before p6, and 11.4-RELEASE before p9, a superuser inside a FreeBSD jail configured with the non-default allow.…
- CVE-2020-25581HIGHCVSS 7.5EG 7.52021-03-26
In FreeBSD 12.2-STABLE before r369312, 11.4-STABLE before r369313, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 due to a race condition in the jail_remove(2) implementation, it may fail to kill some of the processes.
- CVE-2021-22974HIGHCVSS 7.5EG 7.52021-02-12
On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, and 13.1.x before 13.1.3.6 and all versions of BIG-IQ 7.x and 6.x, an authenticated attacker with access to iControl REST over the control plane may be…
- CVE-2020-16021HIGHCVSS 7.5EG 7.52021-01-08
Race in image burner in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to perform OS-level privilege escalation via a malicious file.
- CVE-2020-3966HIGHCVSS 7.5EG 7.52020-06-25
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a heap-overflow due to a race condition issue…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →