Skip to main content

CWE archive

CWE-362 CVEs

Programmatic archive

2,536 CVEs tagged with CWE-36279 Critical, 1,254 High, 1,085 Medium, 118 Low, 0 Unrated.

CVE-2026-32887

Published Mar 20, 2026

Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applications. Prior to version 3.20.0, when using `RpcServer.toWebHa…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-23271

Published Mar 20, 2026

In the Linux kernel, the following vulnerability has been resolved: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race Make sure that __perf_event_overflow() r…

CVSS 7.8 · High
evidence mentions
9
Buzz score
38.0
Vendor/product tagsBeta · best-effort

CVE-2026-32018

Published Mar 19, 2026

OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegistryEntry operations for sandbox containers and browsers. At…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-32723

Published Mar 18, 2026

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global tick state (`currentTicks.current`) is shared between sand…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32700

Published Mar 18, 2026

Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Confirmable module allows an attacker to confirm an email addr…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-32398

Published Mar 13, 2026

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Subrata Mal TeraWallet – For WooCommerce woo-wallet allows Leveraging…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-32242

Published Mar 12, 2026

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth ada…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-31827

Published Mar 10, 2026

Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops and recreates the MongoDB TTL index on the entire post coll…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31824

Published Mar 10, 2026

Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same c…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-0121

Published Mar 10, 2026

In VPU, there is a possible use-after-free read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User inter…

CVSS 2.9 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-0112

Published Mar 10, 2026

In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileg…

CVSS 7.4 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-24297

Published Mar 10, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-24296

Published Mar 10, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileg…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-24295

Published Mar 10, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileg…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-23671

Published Mar 10, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate pri…

CVSS 7.0 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-23668

Published Mar 10, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges loc…

CVSS 7.0 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-23240

Published Mar 10, 2026

In the Linux kernel, the following vulnerability has been resolved: tls: Fix race condition in tls_sw_cancel_work_tx() This issue was discovered during a code audit. After canc…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-23239

Published Mar 10, 2026

In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-28789

Published Mar 5, 2026

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28551

Published Mar 5, 2026

Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28549

Published Mar 5, 2026

Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.6 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28550

Published Mar 5, 2026

Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 4.0 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28545

Published Mar 5, 2026

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28544

Published Mar 5, 2026

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-28543

Published Mar 5, 2026

Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 4.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 351-375 of 2,536 CVEsPage 15 of 102