CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,529 vulnerabilities with CWE-362
CVE-2026-42913 HIGH
Remote Desktop Client Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-42912 HIGH
Microsoft Windows 10 Version 1607 - Windows Telephony Service Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-42909 HIGH
Remote Desktop Client Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-42836 HIGH
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVSS 7.0
CVE-2026-11677 HIGH
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.3
CVE-2026-46298 MEDIUM
pseries/papr-hvpipe: Fix race with interrupt handler
CVSS 4.7
CVE-2026-46275 HIGH
Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths
CVSS 7.8
CVE-2026-11253 MEDIUM
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 4.3
CVE-2026-11145 MEDIUM
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 5.3
CVE-2026-10940 HIGH
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 8.3
CVE-2026-46272 MEDIUM
coresight: tmc-etr: Fix race condition between sysfs and perf mode
CVSS 4.7
CVE-2026-10565 LOW
Open5GS NGAP Handover gmm-sm.c gmm_state_security_mode race condition
CVSS 3.1
CVE-2026-9831 MEDIUM
ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
CVSS 6.3
CVE-2026-47741 MEDIUM
Shopper: Race condition on Discount.usage_limit allows silent over-redemption
CVSS 5.9
CVE-2026-9959 LOW
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 3.1
CVE-2026-10006 HIGH
Google Chrome - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSS 7.5
CVE-2026-46187 MEDIUM
wifi: rsi: fix kthread lifetime race between self-exit and external-stop
CVSS 4.7
CVE-2026-46157 HIGH
ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
CVSS 7.8
CVE-2026-46137 CRITICAL
mptcp: pm: ADD_ADDR rtx: fix potential data-race
CVSS 9.8
CVE-2026-46135 CRITICAL
nvmet-tcp: fix race between ICReq handling and queue teardown
CVSS 9.8
CVE-2026-47270 MEDIUM
pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result
CVSS 6.3
CVE-2026-48066 MEDIUM
pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication
CVSS 5.7
CVE-2026-45090 HIGH
Dalfox: Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
CVSS 7.5
CVE-2026-44318 MEDIUM
free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
CVSS 6.5
CVE-2026-5516 MEDIUM
IBM WebSphere Application Server Liberty is affected by a security bypass vulnerability
CVSS 4.4
Details
Vulnerabilities 2,529
Exploit Likelihood Medium