CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,498 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 41 of 50
- CVE-2025-52515MEDIUMCVSS 5.1EG 5.12026-01-05
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in an out-of-bounds access, leading to a denial of s…
- CVE-2025-52517MEDIUMCVSS 5.9EG 5.92026-01-05
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in a double free, leading to a denial of service.
- CVE-2025-52993MEDIUMCVSS 5.6EG 5.62025-06-27
A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; …
- CVE-2025-53132HIGHCVSS 7.8EG 8.02025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2025-53135HIGHCVSS 7.0EG 7.02025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
- CVE-2025-53150HIGHCVSS 7.8EG 7.82025-10-14
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
- CVE-2025-53768HIGHCVSS 7.8EG 7.82025-10-14
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
- CVE-2025-53807HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-54092HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-54105HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2025-54108HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2025-54114HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-54115HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-54601HIGHCVSS 7.0EG 7.02026-04-06
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a double free…
- CVE-2025-54602HIGHCVSS 7.0EG 7.02026-04-06
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-f…
- CVE-2025-54629MEDIUMCVSS 6.7EG 6.72025-08-06
Race condition issue occurring in the physical page import process of the memory management module. Impact: Successful exploitation of this vulnerability may affect service integrity.
- CVE-2025-54651MEDIUMCVSS 4.8EG 4.82025-08-06
Race condition vulnerability in the kernel hufs module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2025-54913HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapControlSettings allows an authorized attacker to elevate privileges locally.
- CVE-2025-54919HIGHCVSS 7.5EG 7.52025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- CVE-2025-54955HIGHCVSS 8.1EG 8.12025-08-03
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race condition that can lead to full account takeover. By exploiting this, an unauthenticated attacker can obtain a valid JSO…
- CVE-2025-54973MEDIUMCVSS 5.3EG 5.32025-10-14
A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10 and before 7.0.13 allows…
- CVE-2025-55191MEDIUMCVSS 6.5EG 6.52025-09-30
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Versions between 2.1.0 and 2.14.19, 3.2.0-rc1, 3.1.0-rc1 through 3.1.7, and 3.0.0-rc1 through 3.0.18 contain a race condition in the repository credentials handler t…
- CVE-2025-55223HIGHCVSS 7.0EG 7.02025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2025-55224HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- CVE-2025-55226MEDIUMCVSS 6.7EG 6.72025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally.
- CVE-2025-55228HIGHCVSS 7.8EG 7.82025-09-09
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
- CVE-2025-55231HIGHCVSS 7.5EG 7.52025-08-21
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
- CVE-2025-55328HIGHCVSS 7.8EG 7.82025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
- CVE-2025-55335HIGHCVSS 7.4EG 7.42025-10-14
Use after free in Windows NTFS allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-55687HIGHCVSS 7.4EG 7.42025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Resilient File System (ReFS) allows an unauthorized attacker to elevate privileges locally.
- CVE-2025-58145HIGHCVSS 7.5EG 7.52025-09-11
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issues related to the mapping of pages belonging to other domains: For one, an assertion is wro…
- CVE-2025-58296HIGHCVSS 7.5EG 7.52025-09-05
Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect function stability.
- CVE-2025-58303HIGHCVSS 8.4EG 8.42025-11-28
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58313MEDIUMCVSS 5.1EG 5.12025-09-05
Race condition vulnerability in the device standby module. Impact: Successful exploitation of this vulnerability may cause feature exceptions of the device standby module.
- CVE-2025-58316HIGHCVSS 7.3EG 7.32025-11-28
DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2025-58727HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-59052HIGHCVSS 7.1EG 7.12025-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side ren…
- CVE-2025-59193HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2025-59195HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
- CVE-2025-59196HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-59200HIGHCVSS 7.7EG 7.72025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Data Sharing Service Client allows an unauthorized attacker to perform spoofing locally.
- CVE-2025-59205HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-59216HIGHCVSS 7.0EG 7.02025-09-18
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
- CVE-2025-59220HIGHCVSS 7.0EG 7.02025-09-18
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2025-59282HIGHCVSS 7.0EG 7.02025-10-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
- CVE-2025-59455MEDIUMCVSS 4.2EG 4.22025-09-17
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
- CVE-2025-59506HIGHCVSS 7.0EG 7.02025-11-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
- CVE-2025-59507HIGHCVSS 7.0EG 7.02025-11-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2025-59508HIGHCVSS 7.0EG 7.02025-11-11
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2025-59577MEDIUMCVSS 4.3EG 4.32025-09-22
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Leveraging Race Conditions.This issue affects MasterStu…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →