CWE-362
Medium likelihoodConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
2,269 vulnerabilities with CWE-362
CVE-2026-34851
LOW
Huawei HarmonyOS <5.1.0 - DoS
CVSS 2.2
CVE-2026-34850
LOW
Huawei HarmonyOS <5.1.0 - DoS
CVSS 1.9
CVE-2026-40178
MEDIUM
ajenti.plugin.core has a race conditions in 2FA
CVSS 5.9
CVE-2026-5774
MEDIUM
Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map
CVSS 6.4
CVE-2026-5902
CRITICAL
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 9.8
CVE-2026-5893
MEDIUM
Google Chrome <147.0.7727.55 - Memory Corruption
CVSS 6.8
CVE-2026-5890
MEDIUM
Google Chrome <147.0.7727.55 - Info Disclosure
CVSS 5.3
CVE-2026-39880
MEDIUM
Remnawave Backend has a race condition in HWID device limit allows bypassing max devices
CVSS 5.0
CVE-2026-35554
HIGH
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
CVSS 8.7
CVE-2026-23441
MEDIUM
net/mlx5e: Prevent concurrent access to IPSec ASO context
CVSS 4.7
CVE-2026-23440
HIGH
net/mlx5e: Fix race condition during IPSec ESN update
CVSS 7.5
CVE-2026-33544
HIGH
Tinyauth has OAuth account confusion via shared mutable state on singleton service instances
CVSS 7.7
CVE-2026-35099
HIGH
Lakeside Software Systrack Agent < 11.2.1.28 - Privilege Escalation
CVSS 7.4
CVE-2026-34363
MEDIUM
Parse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers
CVSS 5.3
CVE-2026-33028
HIGH
Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse
CVSS 7.5
CVE-2026-33872
HIGH
elixir-nodejs has Cross-User Data Leakage or Information Disclosure due to Worker Protocol Race Condition
CVE-2026-34368
MEDIUM
AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance
CVSS 5.3
CVE-2026-33009
HIGH
EVerest: MQTT Switch-Phases Command Data Race Causing Charger State Corruptio
CVSS 8.2
CVE-2026-27814
MEDIUM
EVerest EvseManager phase-switch path has unsynchronized shared-state access race condition
CVSS 4.2
CVE-2026-26074
HIGH
EVerest: OCPP201 startup event_queue lock mismatch leads to std::map/std::queue data race
CVSS 7.0
CVE-2026-26072
MEDIUM
EVerest has race-condition-induced std::map corruption in OCPP 1.6 evse_soc_map
CVSS 4.2
CVE-2026-26071
MEDIUM
EVerest: OCPP 2.0.1 EVCCID Data Race Leads to Heap Use‑After‑Free
CVSS 4.2
CVE-2026-26070
MEDIUM
EVerest: OCPP 2.0.1 EV SoC Update Race Causes Charge Point Crash
CVSS 4.6
CVE-2026-23393
HIGH
bridge: cfm: Fix race condition in peer_mep deletion
CVSS 7.8
CVE-2026-23348
MEDIUM
cxl: Fix race of nvdimm_bus object when creating nvdimm objects
CVSS 4.7
Details
Vulnerabilities
2,269
Exploit Likelihood
Medium