CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,663 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 47 of 54
- CVE-2026-32153HIGHCVSS 7.8EG 7.82026-04-14
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
- CVE-2026-32158HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-32159HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-32160HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
- CVE-2026-32161HIGHCVSS 7.5EG 7.52026-05-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.
- CVE-2026-32163HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-32164HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-32165HIGHCVSS 7.8EG 7.82026-04-14
Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2026-32219HIGHCVSS 7.0EG 7.02026-04-14
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-32226MEDIUMCVSS 5.9EG 5.92026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
- CVE-2026-32242HIGHCVSS 7.4EG 7.42026-03-12
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly ac…
- CVE-2026-32398MEDIUMCVSS 6.5EG 6.52026-03-13
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Subrata Mal TeraWallet – For WooCommerce woo-wallet allows Leveraging Race Conditions.This issue affects TeraWallet – For WooC…
- CVE-2026-32700MEDIUMCVSS 5.3EG 5.32026-03-18
Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email address they do not own. This affects any Devise application usi…
- CVE-2026-32723MEDIUMCVSS 4.7EG 4.72026-03-18
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global tick state (`currentTicks.current`) is shared between sandboxes. Timer string handlers are compiled at execution time …
- CVE-2026-32848MEDIUMCVSS 4.7EG 4.72026-05-18
NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently issuing CIOCCRYPT operations on the sam…
- CVE-2026-32887HIGHCVSS 7.4EG 7.42026-03-20
Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applications. Prior to version 3.20.0, when using `RpcServer.toWebHandler` (or `HttpApp.toWebHandlerRuntime`) inside a Next.js A…
- CVE-2026-33009MEDIUMCVSS 6.5EG 6.52026-03-26
EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is triggered by an MQTT `everest_external/nodered/{connector}/cmd/switch_three_phases_while_chargi…
- CVE-2026-33028HIGHCVSS 7.5EG 7.52026-03-30
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, co…
- CVE-2026-33104HIGHCVSS 7.0EG 7.02026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2026-33544HIGHCVSS 7.7EG 7.72026-04-02
Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct …
- CVE-2026-33827HIGHCVSS 8.1EG 8.12026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- CVE-2026-33839HIGHCVSS 7.0EG 7.02026-05-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2026-33872HIGHCVSS 7.1EG 7.12026-03-27
elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request…
- CVE-2026-34331HIGHCVSS 7.0EG 7.02026-05-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
- CVE-2026-34334HIGHCVSS 7.8EG 7.82026-05-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-34337HIGHCVSS 7.8EG 7.82026-05-12
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
- CVE-2026-34342HIGHCVSS 7.0EG 7.02026-05-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- CVE-2026-34345HIGHCVSS 7.0EG 7.02026-05-12
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- CVE-2026-34351HIGHCVSS 7.8EG 7.82026-05-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- CVE-2026-34363MEDIUMCVSS 5.3EG 5.32026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process…
- CVE-2026-34368MEDIUMCVSS 5.3EG 5.32026-03-27
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sende…
- CVE-2026-34849LOWCVSS 2.5EG 2.52026-04-13
UAF vulnerability in the screen management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34850LOWCVSS 1.9EG 1.92026-04-13
Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34851LOWCVSS 2.2EG 2.22026-04-13
Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34856HIGHCVSS 7.3EG 7.32026-04-13
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34857MEDIUMCVSS 4.7EG 4.72026-04-13
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34858MEDIUMCVSS 4.1EG 4.12026-04-13
UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34861MEDIUMCVSS 6.3EG 6.32026-04-13
Race condition vulnerability in the thermal management module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-34862MEDIUMCVSS 6.3EG 6.32026-04-13
Race condition vulnerability in the power consumption statistics module. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-35099HIGHCVSS 7.4EG 7.42026-04-01
Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.
- CVE-2026-35554HIGHCVSS 8.7EG 8.72026-04-07
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containi…
- CVE-2026-39880MEDIUMCVSS 4.9EG 4.92026-04-08
Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the HWID device registration logic allows an authenticated user to bypass the configured limit for HWID devices and register…
- CVE-2026-40155MEDIUMCVSS 5.4EG 5.42026-04-17
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requests that trigger a nonce retry may cause the proxy cache fetcher to perform improper look…
- CVE-2026-40178MEDIUMCVSS 5.9EG 5.92026-04-10
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible during a short moment after the authentication of an user to bypass its authentication. This …
- CVE-2026-40943HIGHCVSS 8.7EG 8.72026-04-21
Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel. The heartbeat() method uses a blocking …
- CVE-2026-41458HIGHCVSS 8.2EG 8.22026-04-22
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attac…
- CVE-2026-41913LOWCVSS 3.7EG 3.72026-04-28
OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exploit this by sending multiple simultane…
- CVE-2026-41964HIGHCVSS 8.4EG 8.42026-05-15
Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2026-42099HIGHCVSS 7.5EG 7.52026-05-19
Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__…
- CVE-2026-42487HIGHCVSS 7.9EG 7.92026-06-18
HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those…
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →