CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 3 of 55
- CVE-2022-3071HIGHCVSS 8.8EG 8.82022-09-26
Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
- CVE-2022-3049HIGHCVSS 8.8EG 8.82022-09-26
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-3042HIGHCVSS 8.8EG 8.82022-09-26
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-2857HIGHCVSS 8.8EG 8.82022-09-26
Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-2854HIGHCVSS 8.8EG 8.82022-09-26
Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-2623HIGHCVSS 8.8EG 8.82022-08-12
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- CVE-2022-2617HIGHCVSS 8.8EG 8.82022-08-12
Use after free in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interactions.
- CVE-2022-2609HIGHCVSS 8.8EG 8.82022-08-12
Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- CVE-2022-2608HIGHCVSS 8.8EG 8.82022-08-12
Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- CVE-2022-2607HIGHCVSS 8.8EG 8.82022-08-12
Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- CVE-2021-21165HIGHCVSS 8.8EG 8.82021-03-09
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2020-15670HIGHCVSS 8.8EG 8.82020-10-01
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.…
- CVE-2020-12420HIGHCVSS 8.8EG 8.82020-07-09
When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and …
- CVE-2020-12416HIGHCVSS 8.8EG 8.82020-07-09
A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.
- CVE-2020-6388HIGHCVSS 8.8EG 8.82020-02-11
Out of bounds access in WebAudio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2018-18808HIGHCVSS 8.8EG 8.82019-03-07
The domain management component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jasp…
- CVE-2021-4207HIGHCVSS 8.2EG 8.82022-04-29
A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-ba…
- CVE-2026-50398HIGHCVSS 7.5EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.
- CVE-2026-58608HIGHCVSS 7.5EG 8.82026-07-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.
- CVE-2024-6778HIGHCVSS 7.5EG 8.82024-07-16
Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severit…
- CVE-2026-40943HIGHCVSS 8.7EG 8.72026-04-21
Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel. The heartbeat() method uses a blocking …
- CVE-2026-35554HIGHCVSS 8.7EG 8.72026-04-07
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containi…
- CVE-2026-23735HIGHCVSS 8.7EG 8.72026-01-16
GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are mad…
- CVE-2024-23651HIGHCVSS 8.7EG 8.72024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition t…
- CVE-2020-25582HIGHCVSS 8.7EG 8.72021-03-26
In FreeBSD 12.2-STABLE before r369334, 11.4-STABLE before r369335, 12.2-RELEASE before p4 and 11.4-RELEASE before p8 when a process, such as jexec(8) or killall(1), calls jail_attach(2) to enter a jail, the jailed root can attach to it usi…
- CVE-2024-58045HIGHCVSS 8.6EG 8.62025-03-04
Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-106500HIGHCVSS 8.5EG 8.52026-10-06
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated u…
- CVE-2022-30163HIGHCVSS 8.5EG 8.52022-06-15
Windows Hyper-V Remote Code Execution Vulnerability
- CVE-2021-30465HIGHCVSS 8.5EG 8.52021-05-27
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via …
- CVE-2017-16857HIGHCVSS 8.5EG 8.52017-12-05
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all v…
- CVE-2022-4037HIGHCVSS 6.4EG 8.52023-01-12
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeov…
- CVE-2025-38561HIGHCVSS 4.7EG 8.52025-08-19
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If client send multiple session setup requests to ksmbd, Preauh_HashValue race condition could happen. There is no need to fre…
- CVE-2026-41964HIGHCVSS 8.4EG 8.42026-05-15
Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-32091HIGHCVSS 8.4EG 8.42026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-67505HIGHCVSS 8.4EG 8.42025-12-10
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response hea…
- CVE-2025-58303HIGHCVSS 8.4EG 8.42025-11-28
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-27577HIGHCVSS 8.4EG 8.42025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
- CVE-2025-25278HIGHCVSS 8.4EG 8.42025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through race condition.
- CVE-2024-34732HIGHCVSS 8.4EG 8.42025-01-28
In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is …
- CVE-2024-32997HIGHCVSS 8.4EG 8.42024-05-14
Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2022-22057HIGHCVSS 8.4EG 8.42022-06-14
Use after free in graphics fence due to a race condition while closing fence file descriptor and destroy graphics timeline simultaneously in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdrago…
- CVE-2021-35095HIGHCVSS 8.4EG 8.42022-06-14
Improper serialization of message queue client registration can lead to race condition allowing multiple gunyah message clients to register with same label in Snapdragon Connectivity, Snapdragon Mobile
- CVE-2021-1900HIGHCVSS 8.4EG 8.42021-06-09
Possible use after free in Display due to race condition while creating an external display in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon …
- CVE-2016-0848HIGHCVSS 8.4EG 8.42016-04-18
Race condition in Download Manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to bypass private-storage file-access restrictions via a crafted application that changes a …
- CVE-2024-0041HIGHCVSS 7.0EG 8.42024-02-16
In removePersistentDot of SystemStatusAnimationSchedulerImpl.kt, there is a possible race condition due to a logic error in the code. This could lead to local escalation of privilege that fails to remove the persistent dot with no addition…
- CVE-2026-24930HIGHCVSS 5.5EG 8.42026-02-06
UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-68960HIGHCVSS 4.7EG 8.42026-01-14
Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-68957HIGHCVSS 4.7EG 8.42026-01-14
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-66328HIGHCVSS 4.7EG 8.42025-12-08
Multi-thread race condition vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-106238HIGHCVSS 8.3EG 8.32026-10-06
Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severi…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →