Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Grafana MEDIUM 6.5
CVE-2026-28379

A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fa…

Fix: 11.6.14 / 12.2.8+
Fix from $1,600 2026-05-13
Windows 10 1607 HIGH 7.0
CVE-2026-34345

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34351

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevat…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34342

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized …

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34334

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevat…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-34337

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1809 HIGH 7.0
CVE-2026-33839

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.17763.8755 / 10.0.19044.7291+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.0
CVE-2026-34331

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Windows 10 1607 HIGH 7.5
CVE-2026-32161

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor…

Fix: 10.0.14393.9140 / 10.0.17763.8755+
Fix from $1,950 2026-05-12
Secure Access Client HIGH 7.0
CVE-2026-7432

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

Fix: after 22.7
Fix from $1,950 2026-05-12
Parse Server MEDIUM 5.9
CVE-2026-43930

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race con…

Fix: 8.6.76 / 9.9.0+
Fix from $1,600 2026-05-12
Ipados MEDIUM 5.5
CVE-2026-28996

A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Seq…

Fix: 14.8.7 / 15.7.7+
Fix from $1,600 2026-05-11
Ipados HIGH 7.5
CVE-2026-28986

A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequo…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
macOS HIGH 7.5
CVE-2026-28924

A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Linux Kernel HIGH 7.8
CVE-2026-43353

In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue The HCI DMA dequeue path (hci_d…

Fix: 6.18.19 / 6.19.9+
Fix from $1,950 2026-05-08
Chrome MEDIUM 5.3
CVE-2026-7960

Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensi…

Fix: 148.0.7778.96+
Fix from $1,600 2026-05-06
Chrome HIGH 7.5
CVE-2026-7948

Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. …

Fix: 148.0.7778.96+
Fix from $1,950 2026-05-06
Linux Kernel CRITICAL 9.8
CVE-2026-43198

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock(…

Fix: 6.18.16 / 6.19.6+
Fix from $2,300 2026-05-06
Linux Kernel HIGH 7.8
CVE-2026-43116

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference …

Fix: 6.18.24 / 6.19.14+
Fix from $1,950 2026-05-06
Unclassified MEDIUM 5.0
CVE-2026-7724

A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of the …

Patch available
Fix from $1,600 2026-05-04
Linux Kernel HIGH 7.8
CVE-2026-43023

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() ch…

Fix: 6.1.168 / 6.6.134+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.8
CVE-2026-31761

In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to correct location iio_device_r…

Fix: 5.10.253 / 5.15.203+
Fix from $1,950 2026-05-01
Linux Kernel HIGH 7.8
CVE-2026-31700

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(…

Fix: 6.6.136 / 6.12.84+
Fix from $1,950 2026-05-01
Wazuh MEDIUM 6.5
CVE-2026-26206

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's se…

Fix: 4.14.4+
Fix from $1,600 2026-04-29
Unclassified HIGH 7.0
CVE-2026-3006

Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local p…

Mitigation only
Fix from $1,950 2026-04-27
Chrome HIGH 8.3
CVE-2026-6921

Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video…

Fix: 147.0.7727.116+
Fix from $1,950 2026-04-23
Linux Kernel HIGH 7.8
CVE-2026-31516

In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.work from racing with netns teardown A XFRM_MSG_NE…

Fix: 6.12.80 / 6.18.21+
Fix from $1,950 2026-04-22
Unclassified HIGH 8.2
CVE-2026-41458

OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to c…

Patch available
Fix from $1,950 2026-04-22
Unclassified HIGH 8.7
CVE-2026-40943

Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can caus…

Mitigation only
Fix from $1,950 2026-04-21
Nextjs Auth0 MEDIUM 5.4
CVE-2026-40155

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requ…

Fix: 4.18.0+
Fix from $1,600 2026-04-17