VYPR

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

ClassDraftLikelihood: Medium

Description

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-26 · CAPEC-29

CVEs mapped to this weakness (2,713)

page 9 of 136
  • CVE-2026-28891HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.

  • CVE-2026-28817HigMar 25, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2025-69871HigFeb 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the promotion module. The function performs a non-atomic read-check-update operation when enforcing promotion usage limits. This allows unauthenticated remote…

  • CVE-2026-22856HigJan 14, 2026
    risk 0.53cvss 8.1epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in…

  • CVE-2023-53186HigSep 15, 2025
    risk 0.53cvss 8.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: skbuff: Fix a race between coalescing and releasing SKBs Commit 1effe8ca4e34 ("skbuff: fix coalescing for page_pool fragment recycling") allowed coalescing to proceed with non page pool page and page pool page…

  • CVE-2025-50177HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.04

    Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

  • CVE-2025-7954HigAug 6, 2025
    risk 0.53cvss 8.1epss 0.00

    A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attackers to bypass intended voucher restrictions and exceed usage limitations.

  • CVE-2025-32710HigJun 10, 2025
    risk 0.53cvss 8.1epss 0.01

    Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  • CVE-2025-3886HigApr 27, 2025
    risk 0.53cvss 8.1epss 0.00

    An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.

  • CVE-2025-1801HigMar 3, 2025
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged…

  • CVE-2025-21376HigFeb 11, 2025
    risk 0.53cvss 8.1epss 0.09

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2024-49132HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49128HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  • CVE-2024-49127HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2024-49126HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

  • CVE-2024-49124HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

  • CVE-2024-49123HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49120HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49119HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49118HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability