← Back
CWE-362

2,498 CVEs • Abstraction: Class • Likelihood of Exploit: Medium

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a code sequence that can run concurrently with other code, and the code sequence requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence that is operating concurrently.

JSON object

Loading...

CVEs (2,498)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
5Windows Server 2008
Windows Server 2012Windows Server 2016+2 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
Windows DNS Server Remote Code Execution Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
Windows DNS Server Remote Code Execution Vulnerability
1Microsoft
4Windows Server 2012
Windows Server 2016Windows Server 2019+1 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
Windows DNS Server Remote Code Execution Vulnerability
1Microsoft
8Windows 10
Windows 11Windows 8.1+5 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Windows File Explorer Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Windows Work Folder Service Elevation of Privilege Vulnerability
1Microsoft
10Windows 10
Windows 11Windows 7+7 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Windows ALPC Elevation of Privilege Vulnerability
1Microsoft
6Windows 10
Windows 11Windows Server+3 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Windows Hyper-V Remote Code Execution Vulnerability
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Windows ALPC Elevation of Privilege Vulnerability
1Microsoft
7Windows 10
Windows 11Windows 8.1+4 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Windows Hyper-V Remote Code Execution Vulnerability
1Cisco
4Cgr1000 Compute Module
Ic3000 Industrial Compute GatewayIos+1 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
5.3 MEDIUM· v3
7.6 HIGH· v2
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code...Show more
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) attack against a user of the affected software. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Siemens
4Scalance W1788 1 M12 Firmware
Scalance W1788 2 Eec M12 FirmwareScalance W1788 2 M12 Firmware+1 more
Jun 17, 2026
Apr 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.7 MEDIUM· v2
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions <...Show more
A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versions < V3.0.0), SCALANCE W1788-2 M12 (All versions < V3.0.0), SCALANCE W1788-2IA M12 (All versions < V3.0.0). Affected devices do not properly handle resources of ARP requests. This could allow an attacker to cause a race condition that leads to a crash of the entire device.Show less
1Google
1Android
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
In SUB2AF, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID...Show more
In SUB2AF, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05881290; Issue ID: ALPS05881290.Show less
1Google
1Android
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: A...Show more
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05852819; Issue ID: ALPS05852819.Show less
1Google
1Android
Jun 17, 2026
Apr 11, 2022
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: A...Show more
In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS05837742; Issue ID: ALPS05852812.Show less
4Fedoraproject
LinuxNetapp+1 more
15Active Iq Unified Manager
Enterprise LinuxFedora+12 more
Jun 17, 2026
Apr 8, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
Jun 17, 2026
Apr 5, 2022
N/A· v4
7.0 HIGH· v3
6.2 MEDIUM· v2
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xe...Show more
race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d domain IDs to be leaked and flushes to be bypassed.Show less
1Mirmay
2File Manager
Secure Private Browser
Nov 21, 2024
Mar 28, 2022
N/A· v4
2.5 LOW· v3
1.9 LOW· v2
A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has be...Show more
A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has been disclosed to the public and may be used.Show less
3Linux
NetappOracle
16A700s Firmware
Active Iq Unified ManagerBootstrap Os+13 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges m...Show more
A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (and connect()) in the Linux kernel. In this flaw, an attacker with a user privileges may crash the system or leak internal kernel information.Show less
1Linux
1Linux Kernel
Jun 17, 2026
Mar 25, 2022
N/A· v4
7.0 HIGH· v3
6.9 MEDIUM· v2
A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while t...Show more
A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kernel. This flaw could allow a local attacker with user privileges to cause a data race problem while the device is getting removed, leading to a privilege escalation problem.Show less
3Debian
FedoraprojectParamiko
3Debian Linux
FedoraParamiko
Jun 17, 2026
Mar 17, 2022
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.