CWE-362: CWE-362

466
Total CVEs
6
Critical
254
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
56
2025
214
2024
96
2023
25
2022
23

Top Affected Vendors

1 Linux 173
2 Microsoft 80
3 Google 40
4 Debian 32
5 Huawei 28
6 Apple 28
7 Fedoraproject 13
8 Netapp 11
9 Mozilla 9
10 Xen 8

All CWE-362 CVEs (466)

CVE-2023-49603
7.5

A race condition vulnerability in Intel System Security Report and System Resources Defense firmware allows privileged local users to potentially esca...

Feb 12, 2025
CVE-2024-49353
7.5

This vulnerability in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data allows concurrent resource access without proper input validatio...

Nov 26, 2024
CVE-2023-41833
7.5

A race condition vulnerability in UEFI firmware for certain Intel processors allows a privileged local attacker to potentially escalate privileges. Th...

Sep 16, 2024
CVE-2024-43467
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems running the Remote Desktop Licensing Service. Attackers can ex...

Sep 10, 2024
CVE-2024-45300
7.5

A race condition vulnerability in alf.io allows attackers to bypass promo code usage limits by exploiting timing gaps between validation and enforceme...

Sep 6, 2024
CVE-2024-6778
7.5

A race condition vulnerability in Chrome DevTools allowed malicious extensions to inject scripts or HTML into privileged pages. This affects users run...

Jul 16, 2024
CVE-2024-20007
7.5

This vulnerability in MediaTek's MP3 decoder allows an attacker to execute arbitrary code with elevated privileges through a race condition that cause...

Feb 5, 2024
CVE-2023-6200
7.5

A race condition vulnerability in the Linux kernel's ICMPv6 router advertisement handling allows unauthenticated attackers on adjacent networks to tri...

Jan 28, 2024
CVE-2024-0605
7.5

This vulnerability allows attackers to execute unauthorized JavaScript on websites by exploiting a race condition with javascript: URIs in the URL bar...

Jan 22, 2024
CVE-2024-20700
7.5

This vulnerability allows an authenticated attacker on a guest virtual machine to execute arbitrary code on the Hyper-V host. It affects Windows syste...

Jan 9, 2024
CVE-2023-36884
7.5

CVE-2023-36884 is a remote code execution vulnerability in Windows Search that allows attackers to execute arbitrary code on affected systems. It affe...

Jul 11, 2023
CVE-2023-28232
7.5

This vulnerability allows remote attackers to execute arbitrary code on Windows systems by exploiting a flaw in the Point-to-Point Tunneling Protocol ...

Apr 11, 2023
CVE-2022-48221
7.5

This vulnerability allows a standard user to achieve SYSTEM-level code execution through a race condition and OpLock manipulation in Acuant AcuFill SD...

Apr 4, 2023
CVE-2022-32764
7.5

A race condition vulnerability in Intel Data Streaming Accelerator (DSA) software allows authenticated local users to potentially escalate privileges....

Feb 16, 2023
CVE-2022-26701
7.5

This CVE describes a race condition vulnerability in Apple operating systems that allows an application to execute arbitrary code with kernel privileg...

May 26, 2022
CVE-2021-43411
7.5

This CVE describes a privilege escalation vulnerability in GNU Hurd where during execution of setuid binaries, there's a timing window where the proce...

Nov 7, 2021
CVE-2021-37991
7.5

This vulnerability is a race condition in Chrome's V8 JavaScript engine that could allow a remote attacker to trigger heap corruption by tricking user...

Nov 2, 2021
CVE-2020-29622
7.5

A race condition vulnerability in macOS Catalina's NFS client allows attackers to execute arbitrary code with system privileges by mounting a maliciou...

Oct 19, 2021
CVE-2021-38587
7.5

This vulnerability in cPanel's fix-cpanel-perl script allows local attackers to create arbitrary temporary files due to improper handling of file crea...

Aug 11, 2021
CVE-2021-29952
7.5

A race condition in Firefox's Web Render components during destruction could lead to undefined behavior, potentially allowing arbitrary code execution...

Jun 24, 2021
CVE-2020-25584
7.5

This vulnerability allows a superuser inside a FreeBSD jail with the non-default allow.mount permission to exploit a race condition between directory ...

Apr 7, 2021
CVE-2020-25581
7.5

A race condition in FreeBSD's jail_remove(2) system call may fail to kill some processes when removing a jail, potentially allowing processes to escap...

Mar 26, 2021
CVE-2026-20853
7.4

This vulnerability is a race condition in Windows WalletService that allows local attackers to gain elevated privileges by exploiting improper synchro...

Jan 13, 2026
CVE-2026-20844
7.4

This vulnerability involves a use-after-free flaw in the Windows Clipboard Server that allows an unauthorized local attacker to execute arbitrary code...

Jan 13, 2026
CVE-2025-36934
7.4

This CVE describes a use-after-free vulnerability in the bigo_worker_thread function of Google's Android video processing code. It allows local attack...

Dec 11, 2025
CVE-2025-55687
7.4

A race condition vulnerability in Windows Resilient File System (ReFS) allows local attackers to execute code with elevated privileges by exploiting i...

Oct 14, 2025
CVE-2025-55335
7.4

CVE-2025-55335 is a use-after-free vulnerability in Windows NTFS that allows local attackers to execute arbitrary code with elevated privileges. This ...

Oct 14, 2025
CVE-2024-0397
7.4

A race condition in Python's ssl module allows concurrent calls to cert_store_stats() or get_ca_certs() while certificates are being loaded to cause m...

Jun 17, 2024
CVE-2021-37069
7.4

This CVE describes a race condition vulnerability in Huawei smartphones that could allow attackers to disrupt device availability. The vulnerability a...

Dec 8, 2021
CVE-2021-0244
7.4

A race condition in Juniper Junos OS Layer 2 Address Learning Daemon (L2ALD) allows attackers to bypass storm-control protections during specific admi...

Apr 22, 2021
CVE-2025-58316
7.3

This CVE describes a denial-of-service vulnerability in Huawei's video-related system service module. Attackers can exploit this vulnerability to cras...

Nov 28, 2025
CVE-2025-48548
7.3

This CVE describes a race condition vulnerability in Android's AppOpsControllerImpl.java that allows malicious apps to record audio without displaying...

Sep 4, 2025
CVE-2025-20104
7.3

A race condition vulnerability in Intel Network Adapter Administrative Tools allows authenticated local users to potentially escalate privileges. This...

May 13, 2025
CVE-2023-47111
7.3

This vulnerability allows attackers to bypass ZITADEL's lockout policy by initiating parallel password checks, enabling more password attempts than co...

Nov 8, 2023
CVE-2024-36262
7.2

A race condition vulnerability in Intel System Security Report and System Resources Defense firmware allows privileged users to potentially escalate p...

Feb 12, 2025
CVE-2026-25536
7.1

The CVE-2026-25536 vulnerability in the MCP TypeScript SDK allows cross-client response data leakage when a single server/transport instance is reused...

Feb 4, 2026
CVE-2025-66327
7.1

A race condition vulnerability in the network module could allow attackers to access sensitive information during concurrent operations. This affects ...

Dec 8, 2025
CVE-2025-64168
7.1

A race condition vulnerability in Agno multi-agent framework versions 2.0.0 through 2.2.1 allows session state data to be incorrectly assigned between...

Oct 31, 2025
CVE-2023-3758
7.1

A race condition in SSSD (System Security Services Daemon) causes inconsistent application of Group Policy Object (GPO) policies for authenticated use...

Apr 18, 2024
CVE-2023-46132
7.1

This vulnerability in Hyperledger Fabric allows attackers to manipulate transaction blocks through 'cross-linking' techniques, causing different peers...

Nov 14, 2023
CVE-2026-20617
7.0

A race condition vulnerability in Apple operating systems allows malicious applications to potentially gain root privileges. This affects users runnin...

Feb 11, 2026
CVE-2026-21237
7.0

A race condition vulnerability in Windows Subsystem for Linux allows authenticated local attackers to escalate privileges by exploiting improper synch...

Feb 10, 2026
CVE-2026-21221
7.0

A race condition vulnerability in the Capability Access Management Service (camsvc) allows authorized attackers to escalate privileges on local system...

Jan 13, 2026
CVE-2026-20869
7.0

A race condition vulnerability in Windows Local Session Manager allows authenticated attackers to escalate privileges on affected systems. This affect...

Jan 13, 2026
CVE-2026-20836
7.0

This CVE describes a race condition vulnerability in the Graphics Kernel that allows local attackers with existing system access to elevate privileges...

Jan 13, 2026
CVE-2026-20830
7.0

A race condition vulnerability in the Capability Access Management Service (camsvc) allows authorized attackers to gain elevated privileges on affecte...

Jan 13, 2026
CVE-2026-20814
7.0

This vulnerability is a race condition in the Graphics Kernel that allows an authorized local attacker to execute code concurrently with improper sync...

Jan 13, 2026
CVE-2026-20815
7.0

A race condition vulnerability in the Capability Access Management Service (camsvc) allows authorized attackers to execute concurrent operations on sh...

Jan 13, 2026
CVE-2026-20808
7.0

A race condition vulnerability in the Printer Association Object allows authorized attackers to escalate privileges locally. This affects systems wher...

Jan 13, 2026
CVE-2025-20801
7.0

This CVE describes a memory corruption vulnerability in the seninf component due to a race condition. It allows local privilege escalation from System...

Jan 6, 2026

About CWE-362 (CWE-362)

Our database tracks 466 CVEs classified as CWE-362, with 6 rated critical and 254 rated high severity. The average CVSS score for CWE-362 vulnerabilities is 6.4.

External reference: View CWE-362 on MITRE CWE →

Monitor CWE-362 Vulnerabilities

Get alerted when new CWE-362 CVEs affect your infrastructure.

Start Monitoring Free