Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Windows 10 1607 HIGH 7.8
CVE-2026-26167

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 10 1607 HIGH 7.8
CVE-2026-26168

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,950 2026-04-14
Windows 11 23h2 HIGH 7.0
CVE-2026-25184

Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an …

Fix: 10.0.22631.6936 / 10.0.25398.2274+
Fix from $1,950 2026-04-14
Windows 10 1809 HIGH 7.8
CVE-2026-20930

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,950 2026-04-14
Harmonyos MEDIUM 5.5
CVE-2026-34857

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

Mitigation only
Fix from $1,600 2026-04-13
Harmonyos HIGH 7.5
CVE-2026-34856

UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2026-04-13
Harmonyos HIGH 7.5
CVE-2026-34851

Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,950 2026-04-13
Harmonyos MEDIUM 5.9
CVE-2026-34850

Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2026-04-13
Ajenti Plugin Core MEDIUM 5.9
CVE-2026-40178

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible dur…

Fix: 0.112+
Fix from $1,600 2026-04-10
Juju MEDIUM 6.4
CVE-2026-5774

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possi…

Fix: 2.9.57 / 3.6.21+
Fix from $1,600 2026-04-10
Chrome CRITICAL 9.8
CVE-2026-5902

Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media …

Fix: 147.0.7727.55+
Fix from $2,300 2026-04-08
Chrome MEDIUM 6.8
CVE-2026-5893

Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

Fix: 147.0.7727.55+
Fix from $1,600 2026-04-08
Chrome MEDIUM 5.3
CVE-2026-5890

Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory v…

Fix: 147.0.7727.55+
Fix from $1,600 2026-04-08
Kafka HIGH 8.7
CVE-2026-35554

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. …

Mitigation only
Fix from $1,950 2026-04-07
Exynos 980 Firmware HIGH 7.0
CVE-2025-54601

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W…

Mitigation only
Fix from $1,950 2026-04-06
Exynos 980 Firmware HIGH 7.0
CVE-2025-54602

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W…

Mitigation only
Fix from $1,950 2026-04-06
macOS HIGH 7.5
CVE-2024-40849

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

Fix: 15.1+
Fix from $1,950 2026-04-02
Tinyauth HIGH 7.7
CVE-2026-33544

Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubO…

Fix: 5.0.5+
Fix from $1,950 2026-04-02
Unclassified HIGH 7.4
CVE-2026-35099

Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.2…

Mitigation only
Fix from $1,950 2026-04-01
Linux Kernel HIGH 7.8
CVE-2026-23410

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads …

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-01
Linux Kernel HIGH 7.8
CVE-2026-23411

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was puttin…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-04-01
Parse Server MEDIUM 5.3
CVE-2026-34363

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, w…

Fix: 8.6.65 / 9.7.0+
Fix from $1,600 2026-03-31
Cosy HIGH 7.5
CVE-2026-33028

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to…

Fix: 1.30.1 / 2.3.4+
Fix from $1,950 2026-03-30
Unclassified HIGH 7.1
CVE-2026-33872

elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or …

Patch available
Fix from $1,950 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-34368

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php…

Fix: after 26.0
Fix from $1,600 2026-03-27
Everest MEDIUM 6.5
CVE-2026-33009

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is trigg…

Fix: 2026.02.0+
Fix from $1,600 2026-03-26
Everest HIGH 7.0
CVE-2026-26074

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std::queue>` corruption. The tri…

Fix: 2026.02.0+
Fix from $1,950 2026-03-26
Backup\& Recovery CRITICAL 9.0
CVE-2025-32991

In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.

Fix: 4.3.2+
Fix from $2,300 2026-03-25
Linux Kernel HIGH 7.8
CVE-2026-23393

In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being d…

Fix: 6.12.78 / 6.18.20+
Fix from $1,950 2026-03-25
Linux Kernel HIGH 7.0
CVE-2026-23294

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in devmap on PREEMPT_RT On PREEMPT_RT kernels, the per-CPU xdp_de…

Fix: 6.18.17 / 6.19.7+
Fix from $1,950 2026-03-25