CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,529 vulnerabilities with CWE-362
CVE-2026-43693 HIGH
Apple macOS - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 7.0
CVE-2026-28982 CRITICAL
macOS < 14.8.8, < 15.7.8, < 26.6 - Remote Denial of Service and Kernel Memory Corruption via Race Condition
CVSS 9.8
CVE-2026-28926 HIGH
macOS < 14.8.8 and < 15.7.8 - Privilege Escalation via Race Condition in State Handling
CVSS 7.0
CVE-2026-10681 MEDIUM
SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD)` callers share a kernel-object permission slot
CVSS 6.5
CVE-2026-61079 MEDIUM
Oracle GoldenGate - Denial of Service
CVSS 5.8
CVE-2026-60161 MEDIUM
Oracle VM VirtualBox - Denial of Service
CVSS 6.1
CVE-2026-55219 MEDIUM
Paymenter: Race condition in payWithCredit() enables credit double-spend
CVSS 5.3
CVE-2026-45712 MEDIUM
Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)
CVSS 5.9
CVE-2026-63756 HIGH
SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition
CVSS 8.1
CVE-2026-53400 HIGH
i2c: core: fix adapter registration race
CVSS 7.8
CVE-2026-16212 MEDIUM
awesto django-shop Purchase Stock inventory.py race condition
CVSS 4.2
CVE-2026-16211 LOW
allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname race condition
CVSS 2.6
CVE-2026-16208 MEDIUM
django-tastypie throttle.py CacheDBThrottle race condition
CVSS 5.0
CVE-2026-16082 MEDIUM
Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
CVSS 5.3
CVE-2026-54497 MEDIUM
view_component: Reused Component Instances Retain Stale Render Context
CVSS 6.8
CVE-2026-15995 MEDIUM
IBM Cognos Analytics 12.1.3 GA - Agentic AI Race Condition
CVSS 5.4
CVE-2026-51082 HIGH
Proxmox VE pve-manager <9.1.9/8.4.19 - VNC Proxy/WebSocket Race Condition Session Hijacking
CVSS 7.2
CVE-2026-58598 HIGH
Microsoft Windows 10 Version 21H2 - Windows Backup Service Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-53518 HIGH
Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption
CVSS 8.1
CVE-2026-53517 HIGH
Better Auth OAuth Provider < 1.6.11 - Refresh Token Replay Race Condition
CVSS 8.1
CVE-2026-62294 MEDIUM
Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot "Open With"
CVE-2026-58628 HIGH
Microsoft Windows 10 Version 1809 - Windows Wireless Network Manager Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-58543 MEDIUM
Microsoft Windows 11 Version 24H2 - Universal Print Management Service Elevation of Privilege Vulnerability
CVSS 6.3
CVE-2026-58531 HIGH
Microsoft Windows 10 Version 1607 - Windows SMB Elevation of Privilege Vulnerability
CVSS 7.5
CVE-2026-58527 HIGH
Microsoft Windows 11 Version 24H2 - Windows Runtime Elevation of Privilege Vulnerability
CVSS 7.8
Details
Vulnerabilities 2,529
Exploit Likelihood Medium