Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
HIGH 7.8 CVE-2026-26167 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attack… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-26168 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a… Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,9502026-04-14 HIGH 7.0 CVE-2026-25184 Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an … Windows 11 23h2 10.0.22631.6936 / 10.0.25398.2274+ Fix from $1,9502026-04-14 HIGH 7.8 CVE-2026-20930 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,9502026-04-14 MEDIUM 5.5 CVE-2026-34857 UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos Mitigation only Fix from $1,6002026-04-13 HIGH 7.5 CVE-2026-34856 UAF vulnerability in the communication module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,9502026-04-13 HIGH 7.5 CVE-2026-34851 Race condition vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,9502026-04-13 MEDIUM 5.9 CVE-2026-34850 Race condition vulnerability in the notification service. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002026-04-13 MEDIUM 5.9 CVE-2026-40178 ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was activated, it was possible dur… Ajenti Plugin Core 0.112+ Fix from $1,6002026-04-10 MEDIUM 6.4 CVE-2026-5774 Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possi… Juju 2.9.57 / 3.6.21+ Fix from $1,6002026-04-10 CRITICAL 9.8 CVE-2026-5902 Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media … Chrome 147.0.7727.55+ Fix from $2,3002026-04-08 MEDIUM 6.8 CVE-2026-5893 Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… Chrome 147.0.7727.55+ Fix from $1,6002026-04-08 MEDIUM 5.3 CVE-2026-5890 Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory v… Chrome 147.0.7727.55+ Fix from $1,6002026-04-08 HIGH 8.7 CVE-2026-35554 A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. … Kafka Mitigation only Fix from $1,9502026-04-07 HIGH 7.0 CVE-2025-54601 An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W… Exynos 980 Firmware Mitigation only Fix from $1,9502026-04-06 HIGH 7.0 CVE-2025-54602 An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W… Exynos 980 Firmware Mitigation only Fix from $1,9502026-04-06 HIGH 7.5 CVE-2024-40849 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox. macOS 15.1+ Fix from $1,9502026-04-02 HIGH 7.7 CVE-2026-33544 Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubO… Tinyauth 5.0.5+ Fix from $1,9502026-04-02 HIGH 7.4 CVE-2026-35099 Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.2… Mitigation only Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-23410 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads … Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-01 HIGH 7.8 CVE-2026-23411 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was puttin… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-04-01 MEDIUM 5.3 CVE-2026-34363 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, w… Parse Server 8.6.65 / 9.7.0+ Fix from $1,6002026-03-31 HIGH 7.5 CVE-2026-33028 Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to… Cosy 1.30.1 / 2.3.4+ Fix from $1,9502026-03-30 HIGH 7.1 CVE-2026-33872 elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or … Patch available Fix from $1,9502026-03-27 MEDIUM 5.3 CVE-2026-34368 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php… Avideo after 26.0 Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-33009 EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memory corruption). This is trigg… Everest 2026.02.0+ Fix from $1,6002026-03-26 HIGH 7.0 CVE-2026-26074 EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std::queue>` corruption. The tri… Everest 2026.02.0+ Fix from $1,9502026-03-26 CRITICAL 9.0 CVE-2025-32991 In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. Backup\& Recovery 4.3.2+ Fix from $2,3002026-03-25 HIGH 7.8 CVE-2026-23393 In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletion When a peer MEP is being d… Linux Kernel 6.12.78 / 6.18.20+ Fix from $1,9502026-03-25 HIGH 7.0 CVE-2026-23294 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix race in devmap on PREEMPT_RT On PREEMPT_RT kernels, the per-CPU xdp_de… Linux Kernel 6.18.17 / 6.19.7+ Fix from $1,9502026-03-25