VulnSea

CWE-362

CVEs classified under CWE-362, newest first.

343 CVEsRSS

CVE-2026-78979Medium· 4.3
1mo ago

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page

Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

▾ SunlitGoogle · ChromeEPSS 0.21%via CVEORG
CVE-2026-45404Medium
1mo ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe fo…

▾ Sunlitotel · go.opentelemetry.io/otel/bridge/opentracingEPSS 0.14%via NVD
CVE-2026-77638High· 8.9
1mo ago

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

▾ Twilighttorproject · torEPSS 0.30%via NVD
GHSA-mc9m-6fm9-pghcMedium
1mo ago

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

Zoo Design Studio: Memory-corruption in memory handling of lib-kcl

▾ Sunlitzoo-kcl · zoo-kclvia GHSA
CVE-2026-45742High· 7.5
1mo ago

Gotenberg is a Docker-powered stateless API for PDF files

Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart downloadFrom entry and allows those goroutines…

▾ TwilightEPSS 0.70%via NVD
CVE-2026-62727High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-1199Low· 3.7
1mo ago

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.

▾ Sunlitzabbix · zabbixEPSS 0.17%via NVD
CVE-2026-50139Medium· 5.9
1mo ago

goshs is a SimpleHTTPServer written in Go

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent r…

▾ Sunlitgoshs · goshs.de/goshs/v2EPSS 0.26%via NVD
CVE-2026-64779Low· 3.1⚖ disputed
1mo ago

A memory corruption vulnerability was addressed with improved locking

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted we…

▾ Sunlitapple · ipadosEPSS 0.38%via NVD
CVE-2026-64782Low· 3.1⚖ disputed
1mo ago

A memory corruption vulnerability was addressed with improved locking

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted we…

▾ Sunlitapple · safariEPSS 0.34%via NVD
CVE-2026-64865Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.29%via NVD
CVE-2026-0295High· 7.0⚖ disputed
1mo ago

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…

A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.07%via NVD
CVE-2026-73557Medium
1mo ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses torch.sparse.check_sparse_tensor_invariants, whose process-global save, enable,…

▾ Sunlitvllm · vllmEPSS 0.40%via NVD
CVE-2026-62705High· 7.0
1mo ago

Microsoft Brokering File System Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-62693High· 7.0
1mo ago

Windows MIDI Service Module Elevation of Privileges Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-61927High· 7.0
1mo ago

Windows Bind Filter Driver Elevation of Privilege Vulnerability

Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-62748High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-62729High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-62820High· 8.1
1mo ago

Windows DNS Server Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows Server 2016EPSS 0.54%via CVEORG
CVE-2026-62908High· 7.0
1mo ago

Windows Backup Engine Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-59126High· 7.0
1mo ago

Windows Event Logging Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.20%via CVEORG
CVE-2026-62780High· 7.0
1mo ago

Windows Kernel Elevation of Privilege Vulnerability

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 version 23H2EPSS 0.20%via CVEORG
CVE-2026-62778High· 8.1
1mo ago

Windows DNS Elevation of Privilege Vulnerability

Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.54%via CVEORG
CVE-2026-62734High· 7.0
1mo ago

Windows Telephony Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-66802High· 8.1
1mo ago

Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.54%via CVEORG
CVE-2026-62690High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.20%via NVD
CVE-2026-61920Medium· 6.6
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.

▾ SunlitMicrosoft · Windows Server 2012 R2EPSS 0.52%via NVD
CVE-2026-61352High· 7.5
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.47%via NVD
CVE-2026-61349High· 7.8
1mo ago

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-59122High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CWE-362 vulnerabilities (CVEs) — page 4 · VulnSea