Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Linux Kernel HIGH 7.8
CVE-2026-64260

In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid queue->stopped races and set/read that value under lock There…

Fix: 6.18.39 / 7.1.4+
Fix from $1,950 2026-07-25
Linux Kernel HIGH 7.8
CVE-2026-64600

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_h…

No fix yet
Fix from $1,950 2026-07-23
Goldengate MEDIUM 5.8
CVE-2026-61079

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.0, 21.3-21.21 and 23.4-23.26…

Fix: after 23.26.2.0.0
Fix from $1,600 2026-07-21
Vm Virtualbox MEDIUM 6.1
CVE-2026-60161

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Eas…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.3
CVE-2026-55219

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementatio…

No fix yet
Fix from $1,600 2026-07-20
Linux Kernel HIGH 7.8
CVE-2026-64189

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_list resize The release path…

Fix: 4.20 / 5.10.261+
Fix from $1,950 2026-07-20
Mailpit MEDIUM 5.9
CVE-2026-45712

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-leve…

Fix: 1.30.0+
Fix from $1,600 2026-07-20
Surrealdb HIGH 8.1
CVE-2026-63756

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to …

Fix: 3.1.0+
Fix from $1,950 2026-07-20
Linux Kernel HIGH 7.8
CVE-2026-53400

In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix adapter registration race Adapters can be looked up based on the…

Fix: 5.10.261 / 5.15.212+
Fix from $1,950 2026-07-19
Unclassified MEDIUM 5.0
CVE-2026-16208

A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/thrott…

No fix yet
Fix from $1,600 2026-07-19
Unclassified MEDIUM 5.3
CVE-2026-16082

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipelin…

No fix yet
Fix from $1,600 2026-07-18
View Component MEDIUM 6.8
CVE-2026-54497

view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewCompon…

Fix: 4.12.0+
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.4
CVE-2026-15995

IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.2
CVE-2026-51082

A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4…

No fix yet
Fix from $1,950 2026-07-17
Windows 10 21h2 HIGH 7.0
CVE-2026-58598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to…

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,950 2026-07-16
Better Auth\/oauth Provider HIGH 8.1
CVE-2026-53517

Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oaut…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Better Auth\/oauth Provider HIGH 8.1
CVE-2026-53518

Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/toke…

Fix: 1.6.11+
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.1
CVE-2026-62294

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path…

Mitigation only
Fix from $1,600 2026-07-15
Windows 10 1809 HIGH 7.8
CVE-2026-58628

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attac…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 11 24h2 MEDIUM 6.3
CVE-2026-58543

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker…

Fix: 10.0.26100.8875 / 10.0.26100.33158+
Fix from $1,600 2026-07-14
Windows 11 24h2 HIGH 7.0
CVE-2026-58527

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to eleva…

Fix: 10.0.20348.5386 / 10.0.26100.8875+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.5
CVE-2026-58531

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate p…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.1
CVE-2026-56649

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized att…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 8.1
CVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized a…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-54125

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to eleva…

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.8
CVE-2026-50689

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.8
CVE-2026-50677

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

Fix: 10.0.26100.8875 / 10.0.26200.8875+
Fix from $1,950 2026-07-14
Windows 10 1809 HIGH 7.0
CVE-2026-50672

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9020 / 10.0.19044.7548+
Fix from $1,950 2026-07-14
Windows 11 24h2 HIGH 7.0
CVE-2026-50676

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate…

Fix: 10.0.26100.8875 / 10.0.26200.8875+
Fix from $1,950 2026-07-14
Windows 10 1607 HIGH 7.0
CVE-2026-50667

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate …

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14