← Back
CWE-362

2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibexa
7Commerce
Digital Experience PlatformEz Platform+4 more
Jun 17, 2026
Mar 12, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
2Fedoraproject
Samba
2Fedora
Samba
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
1Apple
1Macos
Jun 17, 2026
Feb 27, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A race condition was addressed with additional validation. This issue is fixed in macOS Ventura 13, macOS Monterey 12.6.1, macOS Big Sur 11.7.1. An app may be able to modify protected parts of the file system.
1Apple
4Ipados
Iphone OsTvos+1 more
Jun 17, 2026
Feb 27, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer A...Show more
A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Feb 22, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race...Show more
An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_remove().Show less
1Mpv
1Mpv
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.
1Intel
1Driver & Support Assistant
Jun 17, 2026
Feb 16, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Google
1Android
Jun 17, 2026
Feb 12, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
In wlan driver, there is a race condition. This could lead to local denial of service in wlan services.
1Answer
1Answer
Jun 17, 2026
Feb 8, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in GitHub repository answerdev/answer prior to 1.0.4.
1Couchbase
1Couchbase Server
Jun 17, 2026
Feb 6, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster mana...Show more
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server node, there is a small window of time (before the cluster management authentication has started) where an attacker can connect to the cluster manager using default credentials.Show less
1Portfoliocms Project
1Portfoliocms
Jun 17, 2026
Feb 3, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php.
1Wireguard
1Wireguard
Jun 17, 2026
Jan 29, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This c...Show more
WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.Show less
1Hfiref0x
1Lightftp
Jun 17, 2026
Jan 21, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName.
1Ssharpsmartthreadpool Project
1Ssharpsmartthreadpool
Nov 21, 2024
Jan 18, 2023
N/A· v4
8.1 HIGH· v3
4.0 MEDIUM· v2
A vulnerability was found in oznetmaster SSharpSmartThreadPool. It has been classified as problematic. This affects an unknown part of the file SSharpSmartThreadPool/SmartThreadPool.cs. The manipulation leads to race con...Show more
A vulnerability was found in oznetmaster SSharpSmartThreadPool. It has been classified as problematic. This affects an unknown part of the file SSharpSmartThreadPool/SmartThreadPool.cs. The manipulation leads to race condition within a thread. The complexity of an attack is rather high. The exploitability is told to be difficult. The patch is named 0e58073c831093aad75e077962e9fb55cad0dc5f. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218463.Show less
1Deno
1Deno
Jun 17, 2026
Jan 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on us...Show more
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to spoof interactive permission prompt by rewriting the prompt to suggest that program is waiting on user confirmation to unrelated action. A malicious program could clear the terminal screen after permission prompt was shown and write a generic message. This situation impacts users who use Web Worker API and relied on interactive permission prompt. The reproduction is very timing sensitive and can’t be reliably reproduced on every try. This problem can not be exploited on systems that do not attach an interactive prompt (for example headless servers). The problem has been fixed in Deno v1.29.3; it is recommended all users update to this version. Users are advised to upgrade. Users unable to upgrade may run with --no-prompt flag to disable interactive permission prompts.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Jan 12, 2023
N/A· v4
8.5 HIGH· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email...Show more
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.Show less
1Microsoft
3Windows 10
Windows 11Windows Server 2022
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Windows Overlay Filter Information Disclosure Vulnerability
1Microsoft
6Windows 10 20h2
Windows 10 21h2Windows 10 22h2+3 more
Jun 17, 2026
Jan 10, 2023
N/A· v4
7.0 HIGH· v3
N/A· v2
Windows Bind Filter Driver Elevation of Privilege Vulnerability
1Microsoft
1Windows Malicious Software Removal Tool
Jun 17, 2026
Jan 10, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability