CWE-362
Medium likelihoodConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
2,378 vulnerabilities with CWE-362
CVE-2026-23294
HIGH
bpf: Fix race in devmap on PREEMPT_RT
CVSS 7.0
CVE-2026-28891
HIGH
macOS <14.8.5 - Privilege Escalation
CVSS 8.1
CVE-2026-28888
MEDIUM
macOS <14.8.5 - Privilege Escalation
CVSS 5.1
CVE-2026-28834
MEDIUM
macOS < 14.8.5, < 15.7.5, < 26.4 - Denial of Service via Race Condition
CVSS 5.1
CVE-2026-28817
HIGH
macOS < 14.8.5, < 15.7.5, < 26.4 - Sandbox Restriction Bypass via Race Condition
CVSS 8.1
CVE-2026-4684
HIGH
Race condition, use-after-free in the Graphics: WebRender component
CVSS 7.5
CVE-2026-4368
HIGH
Race Condition leading to User Session Mixup
CVE-2026-32887
HIGH
Effect Bug: `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC
CVSS 7.4
CVE-2026-23271
HIGH
perf: Fix __perf_event_overflow() vs perf_remove_from_context() race
CVSS 7.8
CVE-2026-32018
LOW
OpenClaw < 2026.2.19 - Race Condition in Sandbox Registry Write Operations
CVSS 3.6
CVE-2026-32723
MEDIUM
SandboxJS timers have an execution-quota bypass (cross-sandbox currentTicks race)
CVSS 4.7
CVE-2026-32700
MEDIUM
Devise <5.0.3 Confirmable Email Change - Race Condition
CVSS 5.3
CVE-2026-32398
MEDIUM
TeraWallet - For WooCommerce <=1.5.15 - Race Condition
CVSS 6.5
CVE-2026-32242
HIGH
Parse Server <9.6.0-alpha.11/8.6.37 - Auth Bypass
CVSS 7.4
CVE-2026-31827
HIGH
Alienbin <= 1.0.0 - Unauthenticated Denial of Service via TTL Index Race Condition
CVE-2026-31824
HIGH
Sylius < 1.9.12 - Unauthenticated Race Condition in Promotion Usage Limit Enforcement
CVSS 8.2
CVE-2026-0121
LOW
Android - Use-After-Free in VPU
CVSS 2.9
CVE-2026-0112
HIGH
Android - Use-After-Free via Race Condition in vpu_open_inst
CVSS 7.4
CVE-2026-24297
MEDIUM
Windows 10/Server 2012/2016 Kerberos Race Condition Security Feature Bypass
CVSS 6.5
CVE-2026-24296
HIGH
Windows Device Association Service - Privilege Escalation
CVSS 7.0
CVE-2026-24295
HIGH
Windows Device Association Service - Privilege Escalation
CVSS 7.0
CVE-2026-23671
HIGH
Windows Bluetooth RFCOM Driver - Privilege Escalation
CVSS 7.0
CVE-2026-23668
HIGH
Microsoft Graphics Component - Privilege Escalation
CVSS 7.0
CVE-2026-23240
CRITICAL
Linux Kernel 5.3-6.12.74, 6.13-6.18.15, 6.19-6.19.5 - Use-After-Free via Race Condition in tls_sw_cancel_work_tx()
CVSS 9.8
CVE-2026-23239
HIGH
Linux Kernel 5.6-6.12.75, 6.13-6.18.16, 6.19-6.19.6 - Use-After-Free via espintcp_close Race Condition
CVSS 7.8
Details
Vulnerabilities
2,378
Exploit Likelihood
Medium