VulnSea

CWE-362

CVEs classified under CWE-362, newest first.

344 CVEsRSS

CVE-2026-54125High· 7.8
2mo ago

Windows Runtime Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.26%via CVEORG
CVE-2026-50689High· 7.8
2mo ago

Windows Clipboard Server Elevation of Privilege Vulnerability

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.26%via CVEORG
CVE-2026-56188Critical· 9.8
2mo ago

Windows Server Network driver Remote Code Execution Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

▾ MidnightMicrosoft · Windows 10 Version 1607EPSS 0.61%via CVEORG
CVE-2026-58531High· 7.5
2mo ago

Windows SMB Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.51%via CVEORG
CVE-2026-58527High· 7.8
2mo ago

Windows Runtime Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.21%via CVEORG
CVE-2026-58543Medium· 6.3
2mo ago

Universal Print Management Service Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.

▾ SunlitMicrosoft · Windows 11 Version 24H2EPSS 0.24%via CVEORG
CVE-2026-58628High· 7.8
2mo ago

Windows Wireless Network Manager Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1809EPSS 0.20%via CVEORG
CVE-2026-56649Medium· 5.9
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

▾ Sunlitmicrosoft · windows_10_1607EPSS 0.70%via NVD
CVE-2026-50322High· 7.0
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.20%via NVD
CVE-2026-50321High· 7.8
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.21%via NVD
CVE-2026-49784High· 7.0
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Windows 10 Version 1607EPSS 0.20%via NVD
CVE-2026-48572High· 7.0
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.20%via NVD
CVE-2026-44800High· 7.8
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.20%via NVD
CVE-2026-42900High· 8.1
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.54%via NVD
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
CVE-2026-35353Low· 3.3
2mo ago

mkdir: -m exposes directory with umask perms before chmod (race window)

mkdir: -m exposes directory with umask perms before chmod (race window)

▾ Sunlituu_mkdir · uu_mkdirEPSS 0.12%via GHSA
CVE-2026-55945Medium· 4.2
2mo ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.19%via NVD
CVE-2026-53352Medium· 4.7
2mo ago

In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a multi-threaded process receives a stop signal (e.g., SIGSTOP), do_signal_stop() sets JOBCTL_…

In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads() When a multi-threaded process receives a stop signal (e.g., SIGSTOP), do_signal_stop() sets JOBCTL_…

▾ Sunlitlinux · linux_kernelEPSS 0.09%via NVD
GHSA-4vgr-h27g-cf9pHigh· 8.1
2mo ago

SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation

SurrealDB: HTTP RPC Session Race Condition Allows Privilege Escalation

▾ Twilightsurrealdb · surrealdbvia GHSA
CVE-2026-55219Medium· 5.3
2mo ago

Paymenter has race condition in payWithCredit() that enables credit double-spend

Paymenter has race condition in payWithCredit() that enables credit double-spend

▾ Sunlitpaymenter · paymenter/paymenterEPSS 0.21%via GHSA
CVE-2026-43743Medium· 4.7
3mo ago

A race condition was addressed with improved state handling

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpe…

▾ Sunlitapple · ipadosEPSS 0.11%via NVD
CVE-2026-13502Medium· 4.5
3mo ago

A flaw has been found in antlr ANTLR4 up to 4.13.2

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This m…

▾ SunlitEPSS 0.11%via NVD
CVE-2026-48505High· 7.4
3mo ago

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission

▾ Twilightfilament · filament/filamentEPSS 0.30%via GHSA
CVE-2026-53050High· 7.8
3mo ago

In the Linux kernel, the following vulnerability has been resolved: quota: Fix race of dquot_scan_active() with quota deactivation dquot_scan_active() can race with quota deactivation in quota_release_workfn() like: CPU0 (quota_rele…

In the Linux kernel, the following vulnerability has been resolved: quota: Fix race of dquot_scan_active() with quota deactivation dquot_scan_active() can race with quota deactivation in quota_release_workfn() like: CPU0 (quota_rele…

▾ Twilightlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-48708High· 7.5
3mo ago

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination

▾ TwilightOliveTin · github.com/OliveTin/OliveTinEPSS 0.54%via GHSA
CVE-2026-54778Medium· 6.2
3mo ago

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

▾ SunlitCoreWCF · CoreWCF.UnixDomainSocketEPSS 0.13%via GHSA
CVE-2025-15546Medium· 5.4
3mo ago

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the fi…

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition between the fi…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-54229High· 7.0
3mo ago

A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method

A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump directory with DD_OPEN_READONLY and calls dd_chown to change ownership of all files to the caller's uid, succeeding even w…

▾ TwilightEPSS 0.12%via NVD
GHSA-chgr-c6px-7xppMedium
3mo ago

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures

▾ Sunlitpyo3 · pyo3via GHSA
CWE-362 vulnerabilities (CVEs) — page 7 · VulnSea