VulnSea

CWE-362

CVEs classified under CWE-362, newest first.

283 CVEsRSS

CVE-2026-61628High· 8.1
today

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the …

Twilightlucasdillmann · nginx-ignitionvia NVD
CVE-2026-94043Medium· 5.3
yesterday

A vulnerability was determined in Free5GC up to 4.2.3

A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_deps/free5gc/NFs/amf/internal/gmm/handler.go of the component Gmm Handler. This manipulation causes race condition. Th…

SunlitEPSS 0.34%via NVD
CVE-2026-71537Medium· 6.5
3d ago

Paymenter is a free and open-source webshop solution for management of hosting services

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…

Sunlitpaymenter · paymenter/paymenterEPSS 0.23%via NVD
CVE-2026-73463Medium· 5.3
5d ago

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently

On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whos…

SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-91723Low· 3.1⚖ disputed
6d ago

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-58734High· 7.0
6d ago

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition

In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

Twilightgoogle · androidEPSS 0.05%via NVD
CVE-2026-58728High· 7.0
6d ago

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition

In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.05%via NVD
CVE-2026-58724High· 7.0
6d ago

In multiple locations, there is a possible use-after-free due to a race condition

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.05%via NVD
CVE-2026-55318High· 8.8
6d ago

In multiple locations, there is a possible use-after-free due to a race condition

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.23%via NVD
CVE-2026-56915Medium· 6.4
6d ago

In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition

In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.05%via NVD
CVE-2026-56964Medium· 6.4
6d ago

In multiple locations, there is a possible use-after-free due to a race condition

In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.05%via NVD
CVE-2026-56923Medium· 6.4
6d ago

In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition

In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for …

Sunlitgoogle · androidEPSS 0.05%via NVD
CVE-2026-56988Medium· 6.4
6d ago

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition

In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitat…

Sunlitgoogle · androidEPSS 0.05%via NVD
CVE-2026-58701High· 7.0
6d ago

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition

In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for expl…

Twilightgoogle · androidEPSS 0.05%via NVD
CVE-2026-58716Medium· 6.7
6d ago

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition

In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.06%via NVD
CVE-2026-91947High· 7.5
6d ago

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock

FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure message…

TwilightFreeRDP · FreeRDPEPSS 0.30%via NVD
CVE-2026-92042High· 7.5
6d ago

Race condition in the DOM: Content Processes component

Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92050Critical· 9.1⚖ disputed
6d ago

Sandbox escape due to race condition in the XPConnect component

Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-84550Medium· 4.7
1w ago

A race condition was addressed with additional validation

A race condition was addressed with additional validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

Sunlitapple · macosEPSS 0.10%via NVD
CVE-2026-84507High· 7.8
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may …

Twilightapple · ipadosEPSS 0.11%via NVD
CVE-2026-65358Medium· 4.7
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpecte…

Sunlitapple · ipadosEPSS 0.11%via NVD
CVE-2026-65401Medium· 5.5
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26.7. An app may be able to cause unexpected system termination.

Sunlitapple · macosEPSS 0.09%via NVD
CVE-2026-65360Medium· 4.7
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may …

Sunlitapple · ipadosEPSS 0.10%via NVD
CVE-2026-65415High· 8.1
1w ago

A race condition was addressed with additional validation

A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. A local user may be able to cause unexpected system termination or read kerne…

Twilightapple · ipadosEPSS 0.25%via NVD
CVE-2026-43783High· 7.8PoC
1w ago

A race condition was addressed with improved locking

A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be able to gain root privileges.

Midnightapple · macosEPSS 0.15%via NVD
CVE-2026-84630Medium· 4.7
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may …

Sunlitapple · ipadosEPSS 0.11%via NVD
CVE-2026-84562Medium· 4.7
1w ago

A race condition was addressed with additional validation

A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to access protected user data.

Sunlitapple · macosEPSS 0.08%via NVD
CVE-2026-84607High· 7.8
1w ago

A race condition was addressed with improved state management

A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandbox…

Twilightapple · ipadosEPSS 0.12%via NVD
CVE-2026-84492Medium· 4.7
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may …

Sunlitapple · ipadosEPSS 0.11%via NVD
CVE-2026-64717Medium· 6.3
1w ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be a…

Sunlitapple · ipadosEPSS 0.10%via NVD
CWE-362 vulnerabilities (CVEs) · VulnSea