CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 16 of 55
- CVE-2025-36934HIGHCVSS 7.4EG 7.42025-12-11
In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2025-12383HIGHCVSS 7.4EG 7.42025-11-18
In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeE…
- CVE-2025-55687HIGHCVSS 7.4EG 7.42025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-55335HIGHCVSS 7.4EG 7.42025-10-14
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-49690HIGHCVSS 7.4EG 7.42025-07-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
- CVE-2024-0397HIGHCVSS 7.4EG 7.42024-06-17
A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called …
- CVE-2023-52553HIGHCVSS 7.4EG 7.42024-04-08
Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2021-37069HIGHCVSS 7.4EG 7.42021-12-08
There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.
- CVE-2021-0244HIGHCVSS 7.4EG 7.42021-04-22
A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS due to the absence of a specific protection mechanism to avoid a race condition which may allow an attacker to bypass the st…
- CVE-2020-11277HIGHCVSS 7.4EG 7.42021-02-22
Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2019-15879HIGHCVSS 7.4EG 7.42020-05-13
In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a race condition in the cryptodev module permitted a data structure in the kernel to be used after it was freed, allowin…
- CVE-2019-2213HIGHCVSS 7.4EG 7.42019-11-13
In binder_free_transaction of binder.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit…
- CVE-2017-12410HIGHCVSS 7.4EG 7.42018-03-26
It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya Virtual System Administrator agent 9.3.0.11 and earlier tries to execute its binaries from working and/or temporary fold…
- CVE-2017-15357HIGHCVSS 7.4EG 7.42017-12-01
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
- CVE-2016-6516HIGHCVSS 7.4EG 7.42016-08-06
Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value…
- CVE-2016-2069HIGHCVSS 7.4EG 7.42016-04-27
Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU.
- CVE-2013-1292HIGHCVSS 7.4EG 7.42013-04-09
Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges v…
- CVE-2013-1278HIGHCVSS 7.4EG 7.42013-02-13
Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local user…
- CVE-2024-34725HIGHCVSS 7.0EG 7.42024-07-09
In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User intera…
- CVE-2025-21701HIGHCVSS 4.7EG 7.42025-02-13
In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and ethnl ops The following trace can be seen if a device is being unregistered while its number of channels are being modi…
- CVE-2026-82543HIGHCVSS 7.3EG 7.32026-08-30
A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit Handler. Performing a manipulation results in race conditi…
- CVE-2026-13197HIGHCVSS 7.3EG 7.32026-08-14
Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in ver…
- CVE-2026-16727HIGHCVSS 7.3EG 7.32026-07-30
Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Se…
- CVE-2026-62432HIGHCVSS 7.3EG 7.32026-07-28
The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in dereferencing a NULL pointer.
- CVE-2026-34856HIGHCVSS 7.3EG 7.32026-04-13
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-48548HIGHCVSS 7.3EG 7.32025-09-04
In multiple functions of AppOpsControllerImpl.java, there is a possible way to record audio without displaying the privacy indicator due to a race condition. This could lead to local escalation of privilege with User execution privileges n…
- CVE-2025-20104HIGHCVSS 7.3EG 7.32025-05-13
Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-8342HIGHCVSS 7.3EG 7.32020-09-15
A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege.
- CVE-2017-14798HIGHCVSS 7.3EG 7.32018-03-01
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
- CVE-2025-58316HIGHCVSS 5.5EG 7.32025-11-28
DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-51082HIGHCVSS 7.2EG 7.22026-07-17
A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PV…
- CVE-2024-36262HIGHCVSS 7.2EG 7.22025-02-12
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2020-25719HIGHCVSS 7.2EG 7.22022-02-18
A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could become confused about the user a ticket represents if it did not strictly require a Kerbero…
- CVE-2014-5195HIGHCVSS v2 7.2EG 7.22014-08-07
Unity before 7.2.3 and 7.3.x before 7.3.1, as used in Ubuntu, does not properly take focus of the keyboard when switching to the lock screen, which allows physically proximate attackers to bypass the lock screen by (1) leveraging a machine…
- CVE-2012-0426HIGHCVSS v2 7.2EG 7.22013-12-02
Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory.
- CVE-2013-4288HIGHCVSS v2 7.2EG 7.22013-10-03
Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_pr…
- CVE-2013-1279HIGHCVSS v2 7.2EG 7.22013-02-13
Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allows local user…
- CVE-2009-1894HIGHCVSS v2 7.2EG 7.22009-07-17
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /p…
- CVE-2009-1238HIGHCVSS v2 7.2EG 7.22009-04-02
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EX…
- CVE-2008-0055HIGHCVSS v2 7.2EG 7.22008-03-18
Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service …
- CVE-2026-77633HIGHCVSS 7.1EG 7.12026-09-22
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional …
- CVE-2026-69364HIGHCVSS 7.1EG 7.12026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
- CVE-2022-26758HIGHCVSS 7.1EG 7.12026-06-10
A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.
- CVE-2026-33872HIGHCVSS 7.1EG 7.12026-03-27
elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request…
- CVE-2026-31827HIGHCVSS 7.1EG 7.12026-03-10
Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops and recreates the MongoDB TTL index on the entire post collection for every new paste submission. When User B submits a…
- CVE-2026-25536HIGHCVSS 7.1EG 7.12026-02-04
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reused across multipl…
- CVE-2025-12472HIGHCVSS 7.1EG 7.12025-11-19
An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbitrary command execution on the Looker instance. Looker-hosted and Self-hosted were foun…
- CVE-2025-64168HIGHCVSS 7.1EG 7.12025-10-31
Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent or Team during run or arun calls, a race condition can occur, causing a session_state to …
- CVE-2025-59052HIGHCVSS 7.1EG 7.12025-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side ren…
- CVE-2023-3758HIGHCVSS 7.1EG 7.12024-04-18
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately.
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →