CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,378 vulnerabilities with CWE-362
CVE-2026-45675 HIGH
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
CVSS 8.1
CVE-2026-41964 HIGH
Huawei HarmonyOS - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.4
CVE-2026-8520 HIGH
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.3
CVE-2026-42594 HIGH
Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async goroutine
CVSS 7.5
CVE-2026-28379 MEDIUM
Viewer-triggered race condition in Grafana Live leads to complete server crash
CVSS 6.5
CVE-2026-34351 HIGH
Microsoft Windows 10 Version 1607 - Windows TCP/IP Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34345 HIGH
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-34342 HIGH
Microsoft Windows 10 Version 1607 - Windows Print Spooler Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-34337 HIGH
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34334 HIGH
Microsoft Windows 10 Version 1607 - Windows TCP/IP Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-34331 HIGH
Windows 10 1607-22H2 and Windows 11 22H3-26H2 - Local Privilege Escalation via Win32K GRFX Race Condition
CVSS 7.0
CVE-2026-33839 HIGH
Microsoft Windows 10 Version 1809 - Win32k Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-32161 HIGH
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-7432 HIGH
Ivanti Secure Access Client - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 7.8
CVE-2026-43930 MEDIUM
Parse Server: MFA SMS one-time password accepted twice under concurrent login
CVSS 5.9
CVE-2026-43659 MEDIUM
iOS and iPadOS < 18.7.9 - Race Condition Leading to Sensitive Data Exposure
CVSS 4.7
CVE-2026-28996 MEDIUM
iOS and iPadOS < 26.5 - Race Condition Leading to Sensitive Data Exposure
CVSS 5.5
CVE-2026-28992 MEDIUM
iOS and iPadOS < 18.7.9 - Denial of Service via Memory Corruption
CVSS 4.7
CVE-2026-28986 HIGH
iOS and iPadOS < 18.7.9 - Denial of Service via Race Condition
CVSS 7.5
CVE-2026-28924 HIGH
macOS - Unauthorized Contacts Access
CVSS 7.5
CVE-2026-28830 MEDIUM
macOS < 26.4 - Unprotected User Data Exposure via Race Condition
CVSS 4.7
CVE-2026-43448 MEDIUM
nvme-pci: Fix race bug in nvme_poll_irqdisable()
CVSS 4.7
CVE-2026-43439 MEDIUM
cgroup: fix race between task migration and iteration
CVSS 4.7
CVE-2026-43430 MEDIUM
usb: yurex: fix race in probe
CVSS 4.7
CVE-2026-43415 MEDIUM
scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend
CVSS 4.7
Details
Vulnerabilities 2,378
Exploit Likelihood Medium