Vulnerability index

Browse CVEs

1,819 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
MEDIUM 6.5 CVE-2026-28379 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fa… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 HIGH 7.0 CVE-2026-34345 Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34351 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34342 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized … Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34334 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevat… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34337 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-33839 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1809 10.0.17763.8755 / 10.0.19044.7291+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-34331 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.5 CVE-2026-32161 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthor… Windows 10 1607 10.0.14393.9140 / 10.0.17763.8755+ Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-7432 A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM Secure Access Client after 22.7 Fix from $1,9502026-05-12 MEDIUM 5.9 CVE-2026-43930 Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race con… Parse Server 8.6.76 / 9.9.0+ Fix from $1,6002026-05-12 MEDIUM 5.5 CVE-2026-28996 A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Seq… Ipados 14.8.7 / 15.7.7+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-28986 A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequo… Ipados 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28924 A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Taho… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.8 CVE-2026-43353 In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue The HCI DMA dequeue path (hci_d… Linux Kernel 6.18.19 / 6.19.9+ Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-7960 Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensi… Chrome 148.0.7778.96+ Fix from $1,6002026-05-06 HIGH 7.5 CVE-2026-7948 Race in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform privilege escalation via a malicious file. … Chrome 148.0.7778.96+ Fix from $1,9502026-05-06 CRITICAL 9.8 CVE-2026-43198 In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock(… Linux Kernel 6.18.16 / 6.19.6+ Fix from $2,3002026-05-06 HIGH 7.8 CVE-2026-43116 In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference … Linux Kernel 6.18.24 / 6.19.14+ Fix from $1,9502026-05-06 MEDIUM 5.0 CVE-2026-7724 A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of the … Patch available Fix from $1,6002026-05-04 HIGH 7.8 CVE-2026-43023 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: fix race conditions in sco_sock_connect() sco_sock_connect() ch… Linux Kernel 6.1.168 / 6.6.134+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-31761 In the Linux kernel, the following vulnerability has been resolved: iio: gyro: mpu3050: Move iio_device_register() to correct location iio_device_r… Linux Kernel 5.10.253 / 5.15.203+ Fix from $1,9502026-05-01 HIGH 7.8 CVE-2026-31700 In the Linux kernel, the following vulnerability has been resolved: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() In tpacket_snd(… Linux Kernel 6.6.136 / 6.12.84+ Fix from $1,9502026-05-01 MEDIUM 6.5 CVE-2026-26206 Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's se… Wazuh 4.14.4+ Fix from $1,6002026-04-29 HIGH 7.0 CVE-2026-3006 Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local p… Mitigation only Fix from $1,9502026-04-27 HIGH 8.3 CVE-2026-6921 Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandbox escape via a crafted video… Chrome 147.0.7727.116+ Fix from $1,9502026-04-23 HIGH 7.8 CVE-2026-31516 In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.work from racing with netns teardown A XFRM_MSG_NE… Linux Kernel 6.12.80 / 6.18.21+ Fix from $1,9502026-04-22 HIGH 8.2 CVE-2026-41458 OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to c… Patch available Fix from $1,9502026-04-22 HIGH 8.7 CVE-2026-40943 Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can caus… Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.4 CVE-2026-40155 The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 through 4.17.1, simultaneous requ… Nextjs Auth0 4.18.0+ Fix from $1,6002026-04-17