Vulnerability index

Browse CVEs

1,823 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Windows 10 1809 HIGH 7.8
CVE-2026-20918

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20867

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20869

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authoriz…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20861

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20866

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1809 HIGH 7.8
CVE-2026-20858

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8276 / 10.0.19044.6809+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.5
CVE-2026-20848

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.4
CVE-2026-20853

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker …

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.4
CVE-2026-20844

Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20836

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20826

Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allow…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows Server 2025 HIGH 7.0
CVE-2026-20830

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.26100.7623+
Fix from $1,950 2026-01-13
Windows 10 1607 HIGH 7.0
CVE-2026-20814

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva…

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.0
CVE-2026-20815

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.26100.7623 / 10.0.26100.32230+
Fix from $1,950 2026-01-13
Windows 11 24h2 HIGH 7.0
CVE-2026-20808

Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attack…

Fix: 10.0.25398.2092 / 10.0.26100.7623+
Fix from $1,950 2026-01-13
Unclassified HIGH 7.8
CVE-2025-71066

In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Always remove class from active list before deleting in ets_qdis…

Mitigation only
Fix from $1,950 2026-01-13
Filelock MEDIUM 5.3
CVE-2026-22701

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock im…

Fix: 3.20.3+
Fix from $1,600 2026-01-10
Axios4go HIGH 8.1
CVE-2026-21697

axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The glob…

Fix: 0.6.4+
Fix from $1,950 2026-01-07
Android HIGH 7.0
CVE-2025-20801

In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has a…

Mitigation only
Fix from $1,950 2026-01-06
Exynos 1330 Firmware MEDIUM 5.1
CVE-2025-52515

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition …

Mitigation only
Fix from $1,600 2026-01-05
Exynos 2500 Firmware MEDIUM 5.9
CVE-2025-52517

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition …

Mitigation only
Fix from $1,600 2026-01-05
Filelock MEDIUM 6.5
CVE-2025-68146

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows loca…

Fix: 3.20.1+
Fix from $1,600 2025-12-16
Nvidia Resiliency Extension HIGH 7.0
CVE-2025-33235

NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A successful …

Fix: 0.5.0+
Fix from $1,950 2025-12-16
Unclassified MEDIUM 6.5
CVE-2025-13231

The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due…

Mitigation only
Fix from $1,600 2025-12-16
Maxkb CRITICAL 10.0
CVE-2025-66419

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environmen…

Fix: 2.4.0+
Fix from $2,300 2025-12-11
Maxkb HIGH 7.5
CVE-2025-66446

MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the b…

Fix: 2.4.0+
Fix from $1,950 2025-12-11
Android HIGH 7.4
CVE-2025-36934

In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to l…

Mitigation only
Fix from $1,950 2025-12-11
Android HIGH 7.0
CVE-2025-36916

In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2025-12-11
Java Management Sdk HIGH 8.4
CVE-2025-67505

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from con…

Fix: 20.0.1+
Fix from $1,950 2025-12-10
Windows 10 1809 HIGH 7.5
CVE-2025-64658

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate…

Fix: 10.0.17763.8146 / 10.0.19044.6691+
Fix from $1,950 2025-12-09