CWE-362

Medium likelihood

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Parent: CWE-662 - Improper Synchronization

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,378 vulnerabilities with CWE-362
CVE-2026-28789 HIGH
olivetin < 3000.10.3 - Unauthenticated Denial of Service via OAuth2 Login Concurrent Map Access
CVSS 7.5
CVE-2026-28551 MEDIUM
HarmonyOS - Denial of Service via Device Security Management Race Condition
CVSS 4.7
CVE-2026-28549 MEDIUM
Permission Management Service - DoS
CVSS 6.6
CVE-2026-28550 MEDIUM
HarmonyOS - Denial of Service via Race Condition in Security Control Module
CVSS 4.0
CVE-2026-28545 MEDIUM
HarmonyOS - Denial of Service via Printing Module Race Condition
CVSS 5.9
CVE-2026-28544 MEDIUM
HarmonyOS - Denial of Service via Printing Module Race Condition
CVSS 6.2
CVE-2026-28543 MEDIUM
Maintenance and Diagnostics Module - DoS
CVSS 4.4
CVE-2026-25674 LOW
Django 6.0-6.0.2,5.2-5.2.11,4.2-4.2.28 - Privilege Escalation
CVSS 3.7
CVE-2026-0995 LOW
Arm C1-Pro <r1p2-50eac0 - Memory Corruption
CVSS 3.6
CVE-2026-2802 MEDIUM
Firefox and Thunderbird < 148.0 - Race Condition in JavaScript GC
CVSS 4.2
CVE-2026-27189 MEDIUM
OpenSift <=1.1.2-alpha - Memory Corruption
CVSS 6.6
CVE-2026-26201 HIGH
emp3r0r < 3.21.2 - Denial of Service via Concurrent Map Access Race Condition
CVSS 7.5
CVE-2026-23207 MEDIUM
Linux Kernel - Race Condition in Tegra210 Quad SPI IRQ Handler
CVSS 4.7
CVE-2026-23169 HIGH
Linux Kernel 5.11.0-6.18.8 - Race Condition in mptcp_pm_nl_flush_addrs_doit
CVSS 7.8
CVE-2026-23167 MEDIUM
Linux Kernel - Use-After-Free in NFC NCI Device Unregistration
CVSS 4.7
CVE-2026-23161 HIGH
Linux Kernel - Race Condition in Shmem Swap Entry Handling
CVSS 7.3
CVE-2026-23153 MEDIUM
Linux Kernel - Race Condition in Firewire Transaction List Handling
CVSS 4.7
CVE-2026-23126 MEDIUM
Linux Kernel Use-After-Free in netdevsim bpf_bound_progs List
CVSS 4.7
CVE-2026-23118 MEDIUM
Linux Kernel 4.17-6.12.68, 6.13-6.18.7, 6.19 - Data Race in rxrpc_peer_keepalive_worker
CVSS 4.7
CVE-2026-23115 MEDIUM
Linux Kernel 6.15-6.18.8 - Race Condition in Serial TTY Port Initialization
CVSS 4.7
CVE-2026-20677 CRITICAL
macOS Tahoe <26.3 - Info Disclosure
CVSS 9.0
CVE-2026-20617 HIGH
Apple watchOS <26.3 - Privilege Escalation
CVSS 7.0
CVE-2026-2319 HIGH
Google Chrome < 145.0.7632.45 - Race Condition in DevTools
CVSS 7.5
CVE-2026-21237 HIGH
Windows Subsystem for Linux - Privilege Escalation
CVSS 7.0
CVE-2026-21234 HIGH
Windows Connected Devices Platform Service - Privilege Escalation
CVSS 7.0
Details
Vulnerabilities 2,378
Exploit Likelihood Medium