Vulnerability index

Browse CVEs

1,823 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
HIGH 7.8 CVE-2026-20918 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20867 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20869 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authoriz… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20861 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20866 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac… Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2026-20858 Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8276 / 10.0.19044.6809+ Fix from $1,9502026-01-13 HIGH 7.5 CVE-2026-20848 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to el… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.4 CVE-2026-20853 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker … Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.4 CVE-2026-20844 Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20836 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20826 Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allow… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20830 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows Server 2025 10.0.26100.7623+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20814 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20815 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows 11 24h2 10.0.26100.7623 / 10.0.26100.32230+ Fix from $1,9502026-01-13 HIGH 7.0 CVE-2026-20808 Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attack… Windows 11 24h2 10.0.25398.2092 / 10.0.26100.7623+ Fix from $1,9502026-01-13 HIGH 7.8 CVE-2025-71066 In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Always remove class from active list before deleting in ets_qdis… Mitigation only Fix from $1,9502026-01-13 MEDIUM 5.3 CVE-2026-22701 filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock im… Filelock 3.20.3+ Fix from $1,6002026-01-10 HIGH 8.1 CVE-2026-21697 axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The glob… Axios4go 0.6.4+ Fix from $1,9502026-01-07 HIGH 7.0 CVE-2025-20801 In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege if a malicious actor has a… Android Mitigation only Fix from $1,9502026-01-06 MEDIUM 5.1 CVE-2025-52515 An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition … Exynos 1330 Firmware Mitigation only Fix from $1,6002026-01-05 MEDIUM 5.9 CVE-2025-52517 An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition … Exynos 2500 Firmware Mitigation only Fix from $1,6002026-01-05 MEDIUM 6.5 CVE-2025-68146 filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows loca… Filelock 3.20.1+ Fix from $1,6002025-12-16 HIGH 7.0 CVE-2025-33235 NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a race condition. A successful … Nvidia Resiliency Extension 0.5.0+ Fix from $1,9502025-12-16 MEDIUM 6.5 CVE-2025-13231 The Fancy Product Designer plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.4.8. This is due… Mitigation only Fix from $1,6002025-12-16 CRITICAL 10.0 CVE-2025-66419 MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environmen… Maxkb 2.4.0+ Fix from $2,3002025-12-11 HIGH 7.5 CVE-2025-66446 MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the b… Maxkb 2.4.0+ Fix from $1,9502025-12-11 HIGH 7.4 CVE-2025-36934 In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race condition. This could lead to l… Android Mitigation only Fix from $1,9502025-12-11 HIGH 7.0 CVE-2025-36916 In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lead to local escalation of priv… Android Mitigation only Fix from $1,9502025-12-11 HIGH 8.4 CVE-2025-67505 Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from con… Java Management Sdk 20.0.1+ Fix from $1,9502025-12-10 HIGH 7.5 CVE-2025-64658 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate… Windows 10 1809 10.0.17763.8146 / 10.0.19044.6691+ Fix from $1,9502025-12-09