VulnSea

CWE-362

CVEs classified under CWE-362, newest first.

283 CVEsRSS

CVE-2026-84522Medium· 5.9
1w ago

A race condition was addressed with improved state management

A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be able to access sensitive user data.

Sunlitapple · macosEPSS 0.19%via NVD
CVE-2026-43690Medium· 4.7
1w ago

A race condition was addressed with improved locking

A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. A local user may be able to read kernel memory.

Sunlitapple · macosEPSS 0.11%via NVD
CVE-2026-18151Medium· 4.2
1w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

SunlitIBM · iEPSS 0.14%via NVD
CVE-2026-85892High· 7.8
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.19%via NVD
CVE-2026-7208Medium· 5.3
1w ago

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…

SunlitYealink · SIP-T33GEPSS 0.23%via NVD
CVE-2026-53715Medium· 5.3
1w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…

Sunlitenvoyproxy · gatewayEPSS 0.36%via NVD
CVE-2026-90506Medium· 5.0PoC
1w ago

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be init…

Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.24%via NVD
CVE-2026-90505Medium· 5.0PoC
1w ago

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attac…

Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.24%via NVD
CVE-2026-89099High· 7.5
1w ago

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-…

TwilightMongoDB · MongoDB ServerEPSS 0.18%via NVD
CVE-2026-50013High· 7.5
1w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy…

TwilightSpectoLabs · hoverflyEPSS 0.27%via NVD
CVE-2026-86744Low· 2.2
1w ago

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForChec…

Sunlitsnipeitapp · snipe-itEPSS 0.21%via NVD
CVE-2026-86766Medium· 6.5PoC
1w ago

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout)

Snipe-IT versions up to and including 8.6.3 contain a race condition (TOCTOU) in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The requested quantity is validated against the number of remainin…

Twilightsnipeitapp · snipe-itEPSS 0.23%via NVD
CVE-2026-87816High· 7.5PoC
1w ago

PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits

PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show e…

Midnightpglombardo · PasswordPusherEPSS 0.29%via NVD
CVE-2026-87467High· 8.1
1w ago

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

Twilightgoogle · chromeEPSS 0.08%via NVD
CVE-2026-87615Medium· 5.4
1w ago

Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page

Race condition in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.14%via NVD
CVE-2026-87641Medium· 4.2
1w ago

Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page

Race condition in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.14%via NVD
CVE-2026-87601High· 7.5
1w ago

Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Twilightgoogle · chromeEPSS 0.18%via NVD
CVE-2026-77063Low· 3.7
1w ago

multer vulnerable to file size limit bypass via async fileFilter race condition

multer vulnerable to file size limit bypass via async fileFilter race condition

Sunlitmulter · multerEPSS 0.16%via GHSA
CVE-2026-28604High· 7.5
1w ago

In multiple locations, there is a possible use after free due to a race condition

In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

Twilightgoogle · androidEPSS 0.21%via NVD
CVE-2026-58848High· 7.0
1w ago

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…

TwilightGoogle · AndroidEPSS 0.06%via NVD
CVE-2026-77894High· 7.0
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.15%via NVD
CVE-2026-73005High· 7.0
1w ago

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

Twilightmicrosoft · windows_10_1607EPSS 0.19%via NVD
CVE-2026-70582Medium· 6.4
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.22%via NVD
CVE-2026-70091Medium· 5.9
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.

Sunlitmicrosoft · windows_10_1607EPSS 0.66%via NVD
CVE-2026-69827High· 8.1
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.53%via NVD
CVE-2026-69799High· 7.8
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.19%via NVD
CVE-2026-69792Medium· 4.7
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to bypass a security feature locally.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.20%via NVD
CVE-2026-69782High· 8.1
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · Windows 10 Version 1607EPSS 0.56%via NVD
CVE-2026-69710High· 7.5
1w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.19%via NVD
CVE-2026-69682High· 7.0
1w ago

Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Host Guardian Service allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · Windows 10 Version 1809EPSS 0.16%via NVD
CWE-362 vulnerabilities (CVEs) — page 2 · VulnSea