Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
HIGH 8.3 CVE-2026-11677 Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perf… Chrome 149.0.7827.103+ Fix from $1,9502026-06-09 HIGH 7.8 CVE-2026-46275 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulne… Linux Kernel 4.15 / 4.20+ Fix from $1,9502026-06-08 MEDIUM 5.3 CVE-2026-11145 Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (… Chrome 149.0.7827.53+ Fix from $1,6002026-06-04 HIGH 8.3 CVE-2026-10940 Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially p… Chrome 149.0.7827.53+ Fix from $1,9502026-06-04 MEDIUM 6.3 CVE-2026-9831 A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions… Mitigation only Fix from $1,6002026-05-29 MEDIUM 5.9 CVE-2026-47741 Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and… Patch available Fix from $1,6002026-05-29 HIGH 7.5 CVE-2026-10006 Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pag… Chrome 148.0.7778.215 / 148.0.7778.216+ Fix from $1,9502026-05-28 HIGH 7.8 CVE-2026-46157 In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger Currently the ru… Linux Kernel 6.12.88 / 6.18.30+ Fix from $1,9502026-05-28 CRITICAL 9.8 CVE-2026-46135 In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_… Linux Kernel 6.12.88 / 6.18.30+ Fix from $2,3002026-05-28 CRITICAL 9.8 CVE-2026-46137 In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() help… Linux Kernel 5.10.259 / 5.15.210+ Fix from $2,3002026-05-28 MEDIUM 6.3 CVE-2026-47270 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM module loaded into the host proce… Patch available Fix from $1,6002026-05-27 MEDIUM 5.7 CVE-2026-48066 pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a process-wide static pointer t… Mitigation only Fix from $1,6002026-05-27 HIGH 7.5 CVE-2026-45090 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pkg/scanning/parameterAnalysis.… Mitigation only Fix from $1,9502026-05-27 MEDIUM 5.3 CVE-2026-44318 free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/subscriptions/{subId} handler … Free5gc 4.2.2+ Fix from $1,6002026-05-27 MEDIUM 5.9 CVE-2026-5516 IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypas… Websphere Application Server after 26.0.0.5 Fix from $1,6002026-05-27 HIGH 7.8 CVE-2026-46058 In the Linux kernel, the following vulnerability has been resolved: media: amphion: Fix race between m2m job_abort and device_run Fix kernel panic … Linux Kernel 6.1.175 / 6.6.140+ Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-45942 In the Linux kernel, the following vulnerability has been resolved: ext4: fix e4b bitmap inconsistency reports A bitmap inconsistency issue was obs… Linux Kernel 6.6.130 / 6.12.75+ Fix from $1,9502026-05-27 HIGH 8.8 CVE-2026-45945 In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix race condition during PASID entry replacement The Intel VT-d PA… Linux Kernel 6.19.4+ Fix from $1,9502026-05-27 HIGH 7.8 CVE-2026-45910 In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix race condition in QP timer handlers I encontered the following wa… Linux Kernel 6.6.128 / 6.12.75+ Fix from $1,9502026-05-27 HIGH 7.0 CVE-2025-46284 A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root… macOS 15.7+ Fix from $1,9502026-05-26 HIGH 8.2 CVE-2026-43981 Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is r… Mitigation only Fix from $1,9502026-05-26 HIGH 8.1 CVE-2026-46727 An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_get… Ruby 4.0.5+ Fix from $1,9502026-05-22 MEDIUM 5.3 CVE-2026-4635 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent … Mattermost Server 10.11.15 / 11.4.5+ Fix from $1,6002026-05-22 MEDIUM 5.9 CVE-2026-5947 Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SI… Bind 9.20.23 / 9.21.22+ Fix from $1,6002026-05-20 HIGH 7.5 CVE-2026-42099 Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties… Pro Cloud Server after 6.1.167 Fix from $1,9502026-05-19 HIGH 7.8 CVE-2026-23558 The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table … Xen Patch available Fix from $1,9502026-05-19 HIGH 8.1 CVE-2026-45675 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP and OAuth authentication … Open Webui 0.9.0+ Fix from $1,9502026-05-15 HIGH 8.4 CVE-2026-41964 Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availability. No fix yet Fix from $1,9502026-05-15 HIGH 8.3 CVE-2026-8520 Race in Payments in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. … Chrome 148.0.7778.168+ Fix from $1,9502026-05-14 HIGH 7.5 CVE-2026-42594 Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the r… Gotenberg 8.32.0+ Fix from $1,9502026-05-14