Vulnerability index

Browse CVEs

1,823 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
HIGH 7.5 CVE-2025-52434 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native … Tomcat 9.0.107+ Fix from $1,9502025-07-10 MEDIUM 5.5 CVE-2025-38290 In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix node corruption in ar->arvifs list In current WLAN recovery c… Linux Kernel 6.6.94 / 6.12.34+ Fix from $1,6002025-07-10 HIGH 7.0 CVE-2025-49744 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49737 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to eleva… Teams 25163.3001.3726.6503+ Fix from $1,9502025-07-08 HIGH 7.4 CVE-2025-49690 Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a… Windows 10 1809 10.0.17763.7558 / 10.0.19044.6093+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-49678 Null pointer dereference in Windows NTFS allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-49665 Concurrent execution using shared resource with improper synchronization ('race condition') in Workspace Broker allows an authorized attacker to elev… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.8 CVE-2025-48000 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.8246 / 10.0.17763.7558+ Fix from $1,9502025-07-08 HIGH 8.0 CVE-2025-47972 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authoriz… Windows 10 1507 10.0.10240.21073 / 10.0.14393.8246+ Fix from $1,9502025-07-08 HIGH 7.0 CVE-2025-1351 IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another user logging in at the same time… Storage Virtualize Mitigation only Fix from $1,9502025-07-07 HIGH 7.0 CVE-2025-38107 In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: fix a race in ets_qdisc_change() Gerrard Tai reported a race co… Linux Kernel 5.5 / 5.10.239+ Fix from $1,9502025-07-03 HIGH 7.0 CVE-2025-38108 In the Linux kernel, the following vulnerability has been resolved: net_sched: red: fix a race in __red_change() Gerrard Tai reported a race condit… Linux Kernel 5.4.295 / 5.10.239+ Fix from $1,9502025-07-03 HIGH 7.0 CVE-2025-38102 In the Linux kernel, the following vulnerability has been resolved: VMCI: fix race between vmci_host_setup_notify and vmci_ctx_unset_notify During … Linux Kernel 5.4.296 / 5.10.240+ Fix from $1,9502025-07-03 MEDIUM 5.6 CVE-2025-52993 A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e… Mitigation only Fix from $1,6002025-06-27 HIGH 7.0 CVE-2022-50082 In the Linux kernel, the following vulnerability has been resolved: ext4: fix warning in ext4_iomap_begin as race between bmap and write We got iss… Linux Kernel 5.10.137 / 5.15.61+ Fix from $1,9502025-06-18 HIGH 7.0 CVE-2022-50014 In the Linux kernel, the following vulnerability has been resolved: mm/gup: fix FOLL_FORCE COW security issue and remove FOLL_COW Ever since the Di… Linux Kernel 5.19.6+ Fix from $1,9502025-06-18 HIGH 7.0 CVE-2022-49939 In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF of ref->proc caused by race condition A transaction of type BIN… Linux Kernel 4.14.293 / 4.19.258+ Fix from $1,9502025-06-18 HIGH 8.1 CVE-2025-32710 Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. Windows Server 2008 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,9502025-06-10 MEDIUM 6.6 CVE-2025-48880 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is… Freescout 1.8.181+ Fix from $1,6002025-05-30 CRITICAL 9.8 CVE-2025-48751 The process_lock crate 0.1.0 for Rust allows data races in unlock. Process Lock No fix yet Fix from $2,3002025-05-24 CRITICAL 9.8 CVE-2025-48753 In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock. Anode Mitigation only Fix from $2,3002025-05-24 MEDIUM 5.9 CVE-2025-0372 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Priv… Mitigation only Fix from $1,6002025-05-21 HIGH 7.3 CVE-2025-20104 Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potenti… Mitigation only Fix from $1,9502025-05-13 MEDIUM 6.6 CVE-2025-20039 Race condition for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentially ena… Proset\/wireless Wifi 23.100.0+ Fix from $1,6002025-05-13 MEDIUM 5.9 CVE-2025-30394EPSS 30% Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network. Windows Server 2012 10.0.14393.8066 / 10.0.17763.7314+ Fix from $1,6002025-05-13 HIGH 7.0 CVE-2025-29841 Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorize… Windows 10 21h2 10.0.19044.5854 / 10.0.19045.5854+ Fix from $1,9502025-05-13 HIGH 7.0 CVE-2025-27468 Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. Windows 10 1507 10.0.10240.21014 / 10.0.14393.8066+ Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-47735 inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization. Wgp after 0.2.0 Fix from $2,3002025-05-09 HIGH 8.1 CVE-2025-47545 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Lev… Poll Maker after 5.7.7 Fix from $1,9502025-05-07 MEDIUM 5.3 CVE-2025-1493 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 12.1.0 through 12.1.1 could allow an authenticated user to cause a denial of … Db2 after 12.1.1 Fix from $1,6002025-05-05