Vulnerability index

Browse CVEs

1,823 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Windows 10 1607 HIGH 7.8
CVE-2025-64661

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate…

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 10 1607 HIGH 7.0
CVE-2025-62573

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8688 / 10.0.17763.8146+
Fix from $1,950 2025-12-09
Windows 11 24h2 HIGH 7.0
CVE-2025-62469

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized a…

Fix: 10.0.26100.7392 / 10.0.26200.7392+
Fix from $1,950 2025-12-09
Android HIGH 7.0
CVE-2025-48625

In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen is off due to a race conditio…

Mitigation only
Fix from $1,950 2025-12-08
Android HIGH 7.0
CVE-2025-48564

In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no add…

Patch available
Fix from $1,950 2025-12-08
Chrome HIGH 7.5
CVE-2025-13721

Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

Fix: 143.0.7499.40 / 143.0.7499.41+
Fix from $1,950 2025-12-02
Harmonyos MEDIUM 5.5
CVE-2025-58316

DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-11-28
Harmonyos MEDIUM 5.5
CVE-2025-64313

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-11-28
Harmonyos MEDIUM 5.5
CVE-2025-58303

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $1,600 2025-11-28
Unclassified HIGH 7.1
CVE-2025-12472

An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbi…

Mitigation only
Fix from $1,950 2025-11-19
Jersey HIGH 7.4
CVE-2025-12383

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, cu…

Mitigation only
Fix from $1,950 2025-11-18
Chrome HIGH 7.5
CVE-2024-7017

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape v…

Fix: 126.0.6478.182+
Fix from $1,950 2025-11-14
Windows 10 1607 HIGH 7.0
CVE-2025-62217

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62218

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an autho…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-62219

Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1809 HIGH 7.0
CVE-2025-62215 KEVEPSS 6%

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,950 2025-11-11
Windows 10 1809 MEDIUM 6.3
CVE-2025-60723

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny …

Fix: 10.0.17763.8027 / 10.0.19044.6575+
Fix from $1,600 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-59506

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to eleva…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-59507

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Windows 10 1607 HIGH 7.0
CVE-2025-59508

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat…

Fix: 10.0.14393.8594 / 10.0.17763.8027+
Fix from $1,950 2025-11-11
Firefox HIGH 7.5
CVE-2025-13012

Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Th…

Fix: 115.30.0 / 140.5.0+
Fix from $1,950 2025-11-11
Chrome HIGH 8.8
CVE-2025-12432

Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu…

Fix: 142.0.7444.59+
Fix from $1,950 2025-11-10
Dottrace HIGH 7.0
CVE-2025-64457

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

Fix: 2025.2.5+
Fix from $1,950 2025-11-10
Hub HIGH 7.5
CVE-2025-64683

In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API

Fix: 2025.3.104432+
Fix from $1,950 2025-11-10
macOS HIGH 7.8
CVE-2025-43364

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may…

Fix: 14.8 / 15.7+
Fix from $1,950 2025-11-04
Unclassified HIGH 7.1
CVE-2025-64168

Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent…

Mitigation only
Fix from $1,950 2025-10-31
Unclassified MEDIUM 6.1
CVE-2025-64118

node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if…

Patch available
Fix from $1,600 2025-10-30
Linux Kernel HIGH 7.0
CVE-2025-39966

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix race during abort for file descriptors fput() doesn't actually cal…

Fix: 6.12.50 / 6.16.10+
Fix from $1,950 2025-10-15
Windows 10 1507 HIGH 7.0
CVE-2025-59282

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to e…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14
Windows 10 1507 HIGH 7.0
CVE-2025-59205

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,950 2025-10-14