Skip to main content

CWE archive

CWE-362 CVEs

Programmatic archive

2,527 CVEs tagged with CWE-36266 Critical, 1,173 High, 1,164 Medium, 118 Low, 6 Unrated.

CVE-2026-44102

Published Jul 30, 2026

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-16727

Published Jul 30, 2026

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privi…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-17993

Published Jul 30, 2026

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-17979

Published Jul 30, 2026

Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-17855

Published Jul 30, 2026

Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a cr…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17841

Published Jul 30, 2026

Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17724

Published Jul 30, 2026

Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium secur…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17712

Published Jul 30, 2026

Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severi…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17711

Published Jul 30, 2026

Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17709

Published Jul 30, 2026

Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a c…

CVSS N/A · Unrated
evidence mentions
2
Buzz score
21.0

CVE-2026-17654

Published Jul 30, 2026

Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity:…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-62436

Published Jul 28, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62435

Published Jul 28, 2026

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] With the introduction of Grant Table v2 came the…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-62432

Published Jul 28, 2026

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct lock. It can race with EVTCHNOP_reset, resulting in derefe…

CVSS 7.3 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-62430

Published Jul 28, 2026

Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest chosen index, and one of the usages of the index didn't take…

CVSS 7.5 · High
evidence mentions
3
Buzz score
25.4

CVE-2026-62429

Published Jul 28, 2026

Accessing the vNUMA configuration data of a guest is still possible when domain destruction has already started. The cleaning up of that configuration information is not synchron…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4

CVE-2026-43811

Published Jul 27, 2026

A race condition was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43781

Published Jul 27, 2026

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensi…

CVSS 4.7 · Medium
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-43770

Published Jul 27, 2026

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. An app may be able to acc…

CVSS 4.7 · Medium
evidence mentions
5
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-43755

Published Jul 27, 2026

A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.

CVSS 7.0 · High
evidence mentions
3
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-43728

Published Jul 27, 2026

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.

CVSS 7.5 · High
evidence mentions
2
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-43693

Published Jul 27, 2026

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root pr…

CVSS 7.0 · High
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28982

Published Jul 27, 2026

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpe…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 2,527 CVEsPage 1 of 102