Vulnerability index

Browse CVEs

1,823 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Tomcat HIGH 7.5
CVE-2025-52434

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native …

Fix: 9.0.107+
Fix from $1,950 2025-07-10
Linux Kernel MEDIUM 5.5
CVE-2025-38290

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix node corruption in ar->arvifs list In current WLAN recovery c…

Fix: 6.6.94 / 6.12.34+
Fix from $1,600 2025-07-10
Windows 10 1507 HIGH 7.0
CVE-2025-49744

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Teams HIGH 7.0
CVE-2025-49737

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to eleva…

Fix: 25163.3001.3726.6503+
Fix from $1,950 2025-07-08
Windows 10 1809 HIGH 7.4
CVE-2025-49690

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…

Fix: 10.0.17763.7558 / 10.0.19044.6093+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.0
CVE-2025-49678

Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 7.8
CVE-2025-49665

Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elev…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Windows 10 1607 HIGH 7.8
CVE-2025-48000

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.8246 / 10.0.17763.7558+
Fix from $1,950 2025-07-08
Windows 10 1507 HIGH 8.0
CVE-2025-47972

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authoriz…

Fix: 10.0.10240.21073 / 10.0.14393.8246+
Fix from $1,950 2025-07-08
Storage Virtualize HIGH 7.0
CVE-2025-1351

IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time…

Mitigation only
Fix from $1,950 2025-07-07
Linux Kernel HIGH 7.0
CVE-2025-38107

In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() Gerrard Tai reported a race co…

Fix: 5.5 / 5.10.239+
Fix from $1,950 2025-07-03
Linux Kernel HIGH 7.0
CVE-2025-38108

In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condit…

Fix: 5.4.295 / 5.10.239+
Fix from $1,950 2025-07-03
Linux Kernel HIGH 7.0
CVE-2025-38102

In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify During …

Fix: 5.4.296 / 5.10.240+
Fix from $1,950 2025-07-03
Unclassified MEDIUM 5.6
CVE-2025-52993

A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e…

Mitigation only
Fix from $1,600 2025-06-27
Linux Kernel HIGH 7.0
CVE-2022-50082

In the Linux kernel, the following vulnerability has been resolved: ext4: fix warning in ext4_iomap_begin as race between bmap and write We got iss…

Fix: 5.10.137 / 5.15.61+
Fix from $1,950 2025-06-18
Linux Kernel HIGH 7.0
CVE-2022-50014

In the Linux kernel, the following vulnerability has been resolved: mm/gup: fix FOLL_FORCE COW security issue and remove FOLL_COW Ever since the Di…

Fix: 5.19.6+
Fix from $1,950 2025-06-18
Linux Kernel HIGH 7.0
CVE-2022-49939

In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF of ref->proc caused by race condition A transaction of type BIN…

Fix: 4.14.293 / 4.19.258+
Fix from $1,950 2025-06-18
Windows Server 2008 HIGH 8.1
CVE-2025-32710

Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,950 2025-06-10
Freescout MEDIUM 6.6
CVE-2025-48880

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is…

Fix: 1.8.181+
Fix from $1,600 2025-05-30
Process Lock CRITICAL 9.8
CVE-2025-48751

The process_lock crate 0.1.0 for Rust allows data races in unlock.

No fix yet
Fix from $2,300 2025-05-24
Anode CRITICAL 9.8
CVE-2025-48753

In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.

Mitigation only
Fix from $2,300 2025-05-24
Unclassified MEDIUM 5.9
CVE-2025-0372

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Priv…

Mitigation only
Fix from $1,600 2025-05-21
Unclassified HIGH 7.3
CVE-2025-20104

Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potenti…

Mitigation only
Fix from $1,950 2025-05-13
Proset\/wireless Wifi MEDIUM 6.6
CVE-2025-20039

Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially ena…

Fix: 23.100.0+
Fix from $1,600 2025-05-13
Windows Server 2012 MEDIUM 5.9
CVE-2025-30394EPSS 30%

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.8066 / 10.0.17763.7314+
Fix from $1,600 2025-05-13
Windows 10 21h2 HIGH 7.0
CVE-2025-29841

Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorize…

Fix: 10.0.19044.5854 / 10.0.19045.5854+
Fix from $1,950 2025-05-13
Windows 10 1507 HIGH 7.0
CVE-2025-27468

Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Fix: 10.0.10240.21014 / 10.0.14393.8066+
Fix from $1,950 2025-05-13
Wgp CRITICAL 9.8
CVE-2025-47735

inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization.

Fix: after 0.2.0
Fix from $2,300 2025-05-09
Poll Maker HIGH 8.1
CVE-2025-47545

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Lev…

Fix: after 5.7.7
Fix from $1,950 2025-05-07
Db2 MEDIUM 5.3
CVE-2025-1493

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of …

Fix: after 12.1.1
Fix from $1,600 2025-05-05