← Back
CWE-362

2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
7Windows 10
Windows 11Windows 8.1+4 more
Jun 17, 2026
Aug 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows Hyper-V Remote Code Execution Vulnerability
1Microsoft
1Edge Chromium
Jun 17, 2026
Aug 9, 2022
N/A· v4
8.3 HIGH· v3
N/A· v2
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
1Frrouting
1Frrouting
Jun 17, 2026
Aug 2, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code...Show more
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.Show less
1Google
1Android
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Pa...Show more
In video codec, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06521260; Issue ID: ALPS06521260.Show less
1Google
1Android
Jun 17, 2026
Aug 1, 2022
N/A· v4
6.4 MEDIUM· v3
N/A· v2
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patc...Show more
In audio ipi, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06478101; Issue ID: ALPS06478101.Show less
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Jul 28, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a...Show more
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Jul 21, 2022
N/A· v4
5.1 MEDIUM· v3
N/A· v2
A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.
1Linux
1Linux Kernel
Jun 17, 2026
Jul 21, 2022
N/A· v4
5.1 MEDIUM· v3
N/A· v2
A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.
1Parallels
1Parallels Desktop
Jun 17, 2026
Jul 18, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the ta...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update machanism. The issue results from the lack of proper locking when performing operations on an object. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-16396.Show less
1Microsoft
3Windows Server 2016
Windows Server 2019Windows Server 2022
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
Windows DNS Server Remote Code Execution Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
Windows Connected Devices Platform Service Information Disclosure Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
6.6 MEDIUM· v3
6.0 MEDIUM· v2
Windows Group Policy Elevation of Privilege Vulnerability
1Octobercms
1October
Jun 17, 2026
Jul 12, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own f...Show more
October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify their own filename in the `fromData` method, an unauthenticated user can perform remote code execution (RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects plugins that expose the `October\Rain\Database\Attach\File::fromData` as a public interface and does not affect vanilla installations of October CMS since this method is not exposed or used by the system internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those who are unable to upgrade may apply with patch to their installation manually as a workaround.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
In MDP, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALP...Show more
In MDP, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06545450; Issue ID: ALPS06545450.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch...Show more
In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641447; Issue ID: ALPS06641447.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch...Show more
In TEEI driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641388; Issue ID: ALPS06641388.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In TEEI driver, there is a possible type confusion due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch...Show more
In TEEI driver, there is a possible type confusion due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06493842; Issue ID: ALPS06493842.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch...Show more
In GED driver, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06641585; Issue ID: ALPS06641585.Show less
1Google
1Android
Jun 17, 2026
Jul 6, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch...Show more
In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07044730; Issue ID: ALPS07044730.Show less
1Dradisframework
1Dradis
Jun 17, 2026
Jun 24, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.