Vulnerability index

Browse CVEs

1,823 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
HIGH 7.8 CVE-2025-64661 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate… Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.0 CVE-2025-62573 Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8688 / 10.0.17763.8146+ Fix from $1,9502025-12-09 HIGH 7.0 CVE-2025-62469 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an authorized a… Windows 11 24h2 10.0.26100.7392 / 10.0.26200.7392+ Fix from $1,9502025-12-09 HIGH 7.0 CVE-2025-48625 In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen is off due to a race conditio… Android Mitigation only Fix from $1,9502025-12-08 HIGH 7.0 CVE-2025-48564 In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no add… Android Patch available Fix from $1,9502025-12-08 HIGH 7.5 CVE-2025-13721 Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… Chrome 143.0.7499.40 / 143.0.7499.41+ Fix from $1,9502025-12-02 MEDIUM 5.5 CVE-2025-58316 DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002025-11-28 MEDIUM 5.5 CVE-2025-64313 Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002025-11-28 MEDIUM 5.5 CVE-2025-58303 UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability. Harmonyos No fix yet Fix from $1,6002025-11-28 HIGH 7.1 CVE-2025-12472 An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbi… Mitigation only Fix from $1,9502025-11-19 HIGH 7.4 CVE-2025-12383 In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, cu… Jersey Mitigation only Fix from $1,9502025-11-18 HIGH 7.5 CVE-2024-7017 Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape v… Chrome 126.0.6478.182+ Fix from $1,9502025-11-14 HIGH 7.0 CVE-2025-62217 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-62218 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an autho… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-62219 Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-62215 KEVEPSS 6% Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat… Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,9502025-11-11 MEDIUM 6.3 CVE-2025-60723 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny … Windows 10 1809 10.0.17763.8027 / 10.0.19044.6575+ Fix from $1,6002025-11-11 HIGH 7.0 CVE-2025-59506 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-59507 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.0 CVE-2025-59508 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.8594 / 10.0.17763.8027+ Fix from $1,9502025-11-11 HIGH 7.5 CVE-2025-13012 Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 115.30, Thunderbird 145, and Th… Firefox 115.30.0 / 140.5.0+ Fix from $1,9502025-11-11 HIGH 8.8 CVE-2025-12432 Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… Chrome 142.0.7444.59+ Fix from $1,9502025-11-10 HIGH 7.0 CVE-2025-64457 In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition Dottrace 2025.2.5+ Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-64683 In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API Hub 2025.3.104432+ Fix from $1,9502025-11-10 HIGH 7.8 CVE-2025-43364 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may… macOS 14.8 / 15.7+ Fix from $1,9502025-11-04 HIGH 7.1 CVE-2025-64168 Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when session_state is passed to Agent… Mitigation only Fix from $1,9502025-10-31 MEDIUM 6.1 CVE-2025-64118 node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if… Patch available Fix from $1,6002025-10-30 HIGH 7.0 CVE-2025-39966 In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix race during abort for file descriptors fput() doesn't actually cal… Linux Kernel 6.12.50 / 6.16.10+ Fix from $1,9502025-10-15 HIGH 7.0 CVE-2025-59282 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to e… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14 HIGH 7.0 CVE-2025-59205 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta… Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,9502025-10-14