CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Description
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-26 · CAPEC-29
CVEs mapped to this weakness (2,608)
page 102 of 131| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-32441 | Med | 0.20 | 4.2 | 0.00 | May 7, 2025 | Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares… | ||
| CVE-2024-7598 | Low | 0.20 | 3.1 | 0.00 | Mar 20, 2025 | A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for… | ||
| CVE-2024-6996 | Low | 0.20 | 3.1 | 0.00 | Aug 6, 2024 | Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | ||
| CVE-2023-49619 | Low | 0.20 | 3.1 | 0.01 | Jan 10, 2024 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number… | ||
| CVE-2023-21262 | Low | 0.20 | 3.1 | 0.00 | Jul 13, 2023 | In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation. | ||
| CVE-2023-2010 | Low | 0.20 | 3.1 | 0.00 | Jul 4, 2023 | The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll. | ||
| CVE-2022-46174 | Med | 0.20 | 4.2 | 0.01 | Dec 28, 2022 | efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to… | ||
| CVE-2022-0279 | Low | 0.20 | 3.1 | 0.00 | Feb 21, 2022 | The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users | ||
| CVE-2021-36181 | Low | 0.20 | 3.1 | 0.00 | Nov 2, 2021 | A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into an inconsistent… | ||
| CVE-2021-24000 | Low | 0.20 | 3.1 | 0.01 | Jun 24, 2021 | A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as <input type="file">) this could have led to an attack where a… | ||
| CVE-2020-15671 | Low | 0.20 | 3.1 | 0.00 | Oct 1, 2020 | When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80. | ||
| CVE-2020-3894 | Low | 0.20 | 3.1 | 0.01 | Apr 1, 2020 | A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory. | ||
| CVE-2016-4583 | Low | 0.20 | 3.1 | 0.02 | Jul 22, 2016 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document. | ||
| CVE-2026-0121 | Low | 0.19 | 2.9 | 0.00 | Mar 10, 2026 | In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2025-48753 | Low | 0.19 | 2.9 | 0.00 | May 24, 2025 | In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock. | ||
| CVE-2025-48751 | Low | 0.19 | 2.9 | 0.00 | May 24, 2025 | The process_lock crate 0.1.0 for Rust allows data races in unlock. | ||
| CVE-2025-47735 | Low | 0.19 | 2.9 | 0.00 | May 9, 2025 | inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization. | ||
| CVE-2025-32793 | Med | 0.19 | 4.0 | 0.00 | Apr 21, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a… | ||
| CVE-2025-64773 | Low | 0.18 | 2.7 | 0.00 | Nov 11, 2025 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit | ||
| CVE-2025-64682 | Low | 0.18 | 2.7 | 0.00 | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit |
- risk 0.20cvss 4.2epss 0.00
Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack session, which allows the unauthenticated user to occupy that session. Rack session middleware prepares…
- risk 0.20cvss 3.1epss 0.00
A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for…
- risk 0.20cvss 3.1epss 0.00
Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- risk 0.20cvss 3.1epss 0.01
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer. This issue affects Apache Answer: through 1.2.0. Under normal circumstances, a user can only bookmark a question once, and will only increase the number…
- risk 0.20cvss 3.1epss 0.00
In startInput of AudioPolicyInterfaceImpl.cpp, there is a possible way of erroneously displaying the microphone privacy indicator due to a race condition. This could lead to false user expectations. User interaction is needed for exploitation.
- risk 0.20cvss 3.1epss 0.00
The Forminator WordPress plugin before 1.24.1 does not use an atomic operation to check whether a user has already voted, and then update that information. This leads to a Race Condition that may allow a single user to vote multiple times on a poll.
- risk 0.20cvss 4.2epss 0.01
efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the Amazon EFS mount helper in efs-utils versions v1.34.3 and below. When using TLS to mount file systems, the mount helper allocates a local port for stunnel to…
- risk 0.20cvss 3.1epss 0.00
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, which could allow any authenticated user to quickly raise their rating or lower the rating of other users
- risk 0.20cvss 3.1epss 0.00
A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into an inconsistent…
- risk 0.20cvss 3.1epss 0.01
A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as <input type="file">) this could have led to an attack where a…
- risk 0.20cvss 3.1epss 0.00
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
- risk 0.20cvss 3.1epss 0.01
A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restricted memory.
- risk 0.20cvss 3.1epss 0.02
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.
- risk 0.19cvss 2.9epss 0.00
In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.19cvss 2.9epss 0.00
In the anode crate 0.1.0 for Rust, data races can occur in unlock in SpinLock.
- risk 0.19cvss 2.9epss 0.00
The process_lock crate 0.1.0 for Rust allows data races in unlock.
- risk 0.19cvss 2.9epss 0.00
inner::drop in inner.rs in the wgp crate through 0.2.0 for Rust lacks drop_slow thread synchronization.
- risk 0.19cvss 4.0epss 0.00
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Versions 1.15.0 to 1.15.15, 1.16.0 to 1.16.8, and 1.17.0 to 1.17.2, are vulnerable when using Wireguard transparent encryption in a Cilium cluster, packets that originate from a…
- risk 0.18cvss 2.7epss 0.00
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
- risk 0.18cvss 2.7epss 0.00
In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit