CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,711 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 5 of 55
- CVE-2026-53517HIGHCVSS 8.1EG 8.12026-07-07
Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke,…
- CVE-2026-5120HIGHCVSS 8.1EG 8.12026-07-01
A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user.
- CVE-2026-46727HIGHCVSS 8.1EG 8.12026-05-26
An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses n…
- CVE-2026-45675HIGHCVSS 8.1EG 8.12026-05-15
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignmen…
- CVE-2026-33827HIGHCVSS 8.1EG 8.12026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- CVE-2026-28891HIGHCVSS 8.1EG 8.12026-03-25
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.
- CVE-2026-28817HIGHCVSS 8.1EG 8.12026-03-25
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.
- CVE-2025-69871HIGHCVSS 8.1EG 8.12026-02-11
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. Thi…
- CVE-2026-22856HIGHCVSS 8.1EG 8.12026-01-14
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another read…
- CVE-2026-21697HIGHCVSS 8.1EG 8.12026-01-07
axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaultClient` is mutated during request execution without synchronization, directly m…
- CVE-2025-50177HIGHCVSS 8.1EG 8.12025-08-12
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- CVE-2025-7954HIGHCVSS 8.1EG 8.12025-08-06
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.
- CVE-2025-54955HIGHCVSS 8.1EG 8.12025-08-03
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSO…
- CVE-2025-32710HIGHCVSS 8.1EG 8.12025-06-10
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2025-3886HIGHCVSS 8.1EG 8.12025-04-27
An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.
- CVE-2025-21947HIGHCVSS 8.1EG 8.12025-04-01
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix type confusion via race condition when using ipc_msg_send_request req->handle is allocated using ksmbd_acquire_id(&ipc_ida), based on ida_alloc. req->handle f…
- CVE-2025-1801HIGHCVSS 8.1EG 8.12025-03-03
A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to…
- CVE-2025-21376HIGHCVSS 8.1EG 8.12025-02-11
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2024-49132HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49128HIGHCVSS 8.1EG 8.12024-12-12
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- CVE-2024-49127HIGHCVSS 8.1EG 8.12024-12-12
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2024-49126HIGHCVSS 8.1EG 8.12024-12-12
Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability
- CVE-2024-49124HIGHCVSS 8.1EG 8.12024-12-12
Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability
- CVE-2024-49123HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49122HIGHCVSS 8.1EG 8.12024-12-12
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-49120HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49119HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49118HIGHCVSS 8.1EG 8.12024-12-12
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2024-49116HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49115HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49108HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-49106HIGHCVSS 8.1EG 8.12024-12-12
Windows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2024-36623HIGHCVSS 8.1EG 8.12024-11-29
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
- CVE-2024-47870HIGHCVSS 8.1EG 8.12024-10-10
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify the `root` URL used by the Gradio frontend to …
- CVE-2024-7627HIGHCVSS 8.1EG 8.12024-09-05
The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due to writing a temporary file to a publicly accessible directory before performing file val…
- CVE-2024-7589HIGHCVSS 8.1EG 8.12024-08-12
A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default). This signal handler executes in …
- CVE-2023-40077HIGHCVSS 8.1EG 8.12023-12-04
In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploita…
- CVE-2023-20571HIGHCVSS 8.1EG 8.12023-11-14
A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.
- CVE-2023-41774HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41773HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41771HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41770HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41769HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41768HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41767HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41765HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-38166HIGHCVSS 8.1EG 8.12023-10-10
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
- CVE-2023-41915HIGHCVSS 8.1EG 8.12023-09-09
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
- CVE-2023-32258HIGHCVSS 8.1EG 8.12023-07-24
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_LOGOFF and SMB2_CLOSE commands. The issue results from the lack of proper locking when performing…
- CVE-2023-32257HIGHCVSS 8.1EG 8.12023-07-24
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP and SMB2_LOGOFF commands. The issue results from the lack of proper locking when pe…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →