VulnSea

CWE-362

CVEs classified under CWE-362, newest first.

344 CVEsRSS

CVE-2026-59122High· 7.0
1mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.20%via NVD
CVE-2026-71968Medium· 6.7
1mo ago

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memor…

OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers with the ability to load a signed Trusted Application to corrupt secure-world kernel memor…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-70640High· 7.0
1mo ago

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while…

llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while…

▾ Twilightggml · llama.cppEPSS 0.24%via NVD
CVE-2026-43631High· 8.1
1mo ago

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary…

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary…

▾ Twilightggml · llama.cppEPSS 0.57%via NVD
CVE-2026-48154Medium· 5.9
1mo ago

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA …

▾ Sunlitpilinux · github.com/pilinux/gorestEPSS 0.40%via NVD
CVE-2026-64373Medium· 4.7
2mo ago

In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path

In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path. Unlike the normal…

▾ Sunlitlinux · linux_kernelEPSS 0.09%via NVD
CVE-2026-64378High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() When a container exits, the following BUG_ON() is occasionally triggered: ===============…

In the Linux kernel, the following vulnerability has been resolved: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() When a container exits, the following BUG_ON() is occasionally triggered: ===============…

▾ Twilightlinux · linux_kernelEPSS 0.10%via NVD
CVE-2026-64279High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregistration race Adapters can be looked up by their id using i2c_get_adapter() which takes a reference to the embedded struct device. Remove…

In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter deregistration race Adapters can be looked up by their id using i2c_get_adapter() which takes a reference to the embedded struct device. Remove…

▾ Twilightlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-10681Medium· 6.5
2mo ago

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, two user-mo…

In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, two user-mo…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-64600High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.16%via NVD
CVE-2026-59896Medium· 6.5
2mo ago

hono/jsx does not isolate context per request, leading to cross-request data disclosure

hono/jsx does not isolate context per request, leading to cross-request data disclosure

▾ Sunlithono · honoEPSS 0.30%via GHSA
CVE-2026-53400High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registration race Adapters can be looked up based on their id using i2c_get_adapter() which takes a reference to the embedded struct device. Ma…

In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registration race Adapters can be looked up based on their id using i2c_get_adapter() which takes a reference to the embedded struct device. Ma…

▾ Twilightlinux · linux_kernelEPSS 0.10%via NVD
CVE-2026-16212Medium· 4.2
2mo ago

A vulnerability was identified in awesto django-shop up to 1.2.4

A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handler. The manipulation leads to race condition. The attack is possi…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-16211Low· 2.6
2mo ago

A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e

A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation H…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-16208Medium· 5.0
2mo ago

A flaw has been found in django-tastypie up to 0.15.1

A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. This manipulation causes race condition. The attack may be initiated remotely. Th…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-16082Medium· 5.3
2mo ago

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. T…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-58598High· 7.0
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 21H2EPSS 0.20%via NVD
CVE-2026-54497Medium· 6.8
2mo ago

ViewComponent: Reused Component Instances Retain Stale Render Context

ViewComponent: Reused Component Instances Retain Stale Render Context

▾ Sunlitview_component · view_componentEPSS 0.33%via GHSA
CVE-2026-54991High· 7.8
2mo ago

Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.21%via CVEORG
CVE-2026-54112High· 7.8
2mo ago

Windows Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-54111High· 7.0
2mo ago

Universal Print Management Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-54107High· 8.8PoC
2mo ago

Windows Win32k Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.21%via CVEORG
CVE-2026-54999High· 8.8
2mo ago

Windows TCP/IP Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.41%via CVEORG
CVE-2026-54996High· 7.0
2mo ago

Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-58608High· 8.8
2mo ago

Windows Print Spooler Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.57%via CVEORG
CVE-2026-58526High· 7.0
2mo ago

Windows Storage Elevation of Privilege Vulnerability

Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.21%via CVEORG
CVE-2026-49183High· 7.0
2mo ago

Windows Clipboard Server Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-49806High· 7.0
2mo ago

Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CVE-2026-49803High· 7.0
2mo ago

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via CVEORG
CVE-2026-49802High· 7.0
2mo ago

Windows USB Print Driver Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.20%via CVEORG
CWE-362 vulnerabilities (CVEs) — page 5 · VulnSea