CWE-362: Race Condition — known CVE vulnerabilities
CVEs classified under CWE-362 (Race Condition), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2022-27626 — CVSS 10.0 (critical): A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the…
CVE-2014-0703 — CVSS 10.0 (critical): Cisco Wireless LAN Controller (WLC) devices 7.4 before 7.4.110.0 distribute Aironet IOS software with a race condition in the status of the…
CVE-2010-1228 — CVSS 10.0 (critical): Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.
CVE-2008-6598 — CVSS 10.0 (critical): Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."
CVE-2026-64720 — CVSS 9.8 (critical): A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6…
CVE-2026-43805 — CVSS 9.8 (critical): A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS…
CVE-2026-28982 — CVSS 9.8 (critical): A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A…
CVE-2026-56188 — CVSS 9.8 (critical): Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an…
CVE-2026-53086 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: fix racing timeout handler The bcmgenet_timeout handler…
CVE-2026-46137 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This…
CVE-2026-46135 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown…
CVE-2026-43198 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in…
CVE-2026-5902 — CVSS 9.8 (critical): Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to…
CVE-2026-23240 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was…
CVE-2022-50373 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: fs: dlm: fix race in lowcomms This patch fixes a race between…
CVE-2022-50350 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix a race condition between login_work and the…
CVE-2025-39726 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device…
CVE-2025-39673 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path…
CVE-2025-38561 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If client send multiple…
CVE-2025-43275 — CVSS 9.8 (critical): A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura…
CVE-2025-43244 — CVSS 9.8 (critical): A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura…
CVE-2025-30444 — CVSS 9.8 (critical): A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5…
CVE-2022-49201 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: ibmvnic: fix race between xmit and reset There is a race between reset…
CVE-2022-49149 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix call timer start racing with call destruction The rxrpc_call…
CVE-2024-53186 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in SMB request handling A race condition…
CVE-2024-48069 — CVSS 9.8 (critical): A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files…
CVE-2024-39293 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: Revert "xsk: Support redirect to any socket bound to the same umem"…
CVE-2023-52480 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup and expire Thread A +…
CVE-2024-26585 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to…
CVE-2024-26583 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting…
CVE-2023-32254 — CVSS 9.8 (critical): A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of…
CVE-2023-28201 — CVSS 9.8 (critical): This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4…
CVE-2022-44551 — CVSS 9.8 (critical): The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality…
CVE-2022-39328 — CVSS 9.8 (critical): Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race…
CVE-2021-32810 — CVSS 9.8 (critical): crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and…
CVE-2021-26569 — CVSS 9.8 (critical): Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows…
CVE-2020-10279 — CVSS 9.8 (critical): MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating…
CVE-2019-2006 — CVSS 9.8 (critical): In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local…
CVE-2016-0930 — CVSS 9.8 (critical): Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for…
CVE-2026-17855 — CVSS 9.6 (critical): Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to…
CVE-2026-17711 — CVSS 9.6 (critical): Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to…
CVE-2026-17709 — CVSS 9.6 (critical): Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to…
CVE-2026-13882 — CVSS 9.6 (critical): Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially…
CVE-2015-6789 — CVSS 9.3 (critical): Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to…
CVE-2015-5754 — CVSS 9.3 (critical): Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 allows attackers to…
CVE-2014-0100 — CVSS 9.3 (critical): Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to…
CVE-2014-1490 — CVSS 9.3 (critical): Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x…
CVE-2013-7283 — CVSS 9.3 (critical): Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact…
CVE-2012-5108 — CVSS 9.3 (critical): Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.