Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
MEDIUM 5.9 CVE-2026-50139 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.9 CVE-2026-1199 Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block count… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.0 CVE-2026-64865 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user… Fix unknown Fix from $4,0002026-08-17 HIGH 7.3 CVE-2026-13197 Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability … No fix yet Fix from $4,9002026-08-14 MEDIUM 5.9 CVE-2026-13198 Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability … No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-73557 vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-18150 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition. I Fix unknown Fix from $4,0002026-08-12 MEDIUM 5.0 CVE-2026-18250 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a ra… I after 7.6 Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-66802 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health … Windows 10 1809 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62908 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to… Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-62820 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute… Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62780 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. Windows 11 23h2 10.0.22631.7517 / 10.0.26100.9106+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-62778 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network. Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62748 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke… Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62729 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke… Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62734 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke… Windows 10 1607 No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62705 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attack… Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62690 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack… Windows 10 1809 10.0.17763.9115 / 10.0.19044.7663+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-62693 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attac… Windows 11 24h2 10.0.26100.9106 / 10.0.26200.9106+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-61927 Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally. Windows 11 24h2 10.0.26100.9106 / 10.0.26100.33222+ Fix from $4,9002026-08-11 MEDIUM 6.6 CVE-2026-61920 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute c… Windows 10 1607 No fix yet Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-61349 Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-61352 Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker … Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-59122 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke… Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 7.0 CVE-2026-59126 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized att… Windows 10 21h2 10.0.19044.7663 / 10.0.19045.7663+ Fix from $4,9002026-08-11 MEDIUM 6.7 CVE-2026-71968 OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application loader that allows attackers wi… No fix yet Fix from $4,0002026-08-10 MEDIUM 6.8 CVE-2026-9030 A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not p… No fix yet Fix from $1,6002026-08-07 HIGH 7.0 CVE-2026-70640 llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and … No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-43631 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-se… No fix yet Fix from $1,9502026-08-06 HIGH 7.4 CVE-2026-19139 Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via … Chrome 151.0.7922.109+ Fix from $1,9502026-08-06