CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,376 vulnerabilities with CWE-362
CVE-2026-10565 LOW
Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition
CVSS 3.1
CVE-2026-9831 MEDIUM
ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
CVSS 6.3
CVE-2026-47741 MEDIUM
Shopper: Race condition on Discount.usage_limit allows silent over-redemption
CVSS 5.9
CVE-2026-9959 LOW
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 3.1
CVE-2026-10006 HIGH
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 7.5
CVE-2026-46187 MEDIUM
wifi: rsi: fix kthread lifetime race between self-exit and external-stop
CVSS 4.7
CVE-2026-46157 HIGH
ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
CVSS 7.8
CVE-2026-47270 MEDIUM
pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result
CVSS 6.3
CVE-2026-48066 MEDIUM
pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication
CVSS 5.7
CVE-2026-45090 HIGH
Dalfox: Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
CVSS 7.5
CVE-2026-44318 MEDIUM
free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
CVSS 6.5
CVE-2026-5516 MEDIUM
IBM WebSphere Application Server Liberty is affected by a security bypass vulnerability
CVSS 4.4
CVE-2026-44443 MEDIUM
Lumiverse: Sign-up nonce race condition allows unauthorized account registration
CVSS 4.8
CVE-2026-24199 MEDIUM
Nvidia GeForce - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 4.7
CVE-2026-43981 HIGH
Algernon: Race Condition in handle() shared LState
CVE-2026-46727 HIGH
Ruby < 4.0.5 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.1
CVE-2026-4635 MEDIUM
Persistent notification timing attack causing server denial of service
CVSS 6.5
CVE-2026-44059 MEDIUM
Netatalk 2.2.5-4.4.2 and >=4.5.0 - Race Condition in Privilege Toggle Mechanism
CVSS 4.5
CVE-2026-5947 HIGH
SIG(0) validation during query flood may lead to undefined behavior
CVSS 7.5
CVE-2026-42099 HIGH
Race Condition in Sparx Pro Cloud Server
CVSS 7.5
CVE-2026-23558 HIGH
grant table v2 race in status page mapping
CVSS 7.8
CVE-2026-32848 MEDIUM
NetBSD cryptodev Race Condition Double-Free via cryptodev_op()
CVSS 4.7
CVE-2026-8741 LOW
EMQX QoS 2 PUBLISH Packet emqx_persistent_session_ds.erl race condition
CVSS 3.1
CVE-2026-45675 HIGH
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVSS 8.1
CVE-2026-41964 HIGH
Huawei HarmonyOS - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.4
Details
Vulnerabilities 2,376
Exploit Likelihood Medium