CWE-366 · 19 records
Race Condition within a Thread
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-58143No exploit | Mutiple vulnerabilities in the Viridian interfacexen · xen · CWE-366 | Critical9.8 | — | 0.4% | Sep 11, 2025 |
34Monitor | CVE-2025-31115No exploit | XZ has a heap-use-after-free bug in threaded .xz decodertukaani-project · xz · CWE-366 | High8.7 | — | 0.7% | Apr 3, 2025 |
33Monitor | CVE-2021-26569No exploit | Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows rsynology · diskstation manager · CWE-366 | High8.1 | — | 2.2% | Mar 12, 2021 |
32Monitor | CVE-2015-10067No exploit | oznetmaster SSharpSmartThreadPool SmartThreadPool.cs race conditionssharpsmartthreadpool project · ssharpsmartthreadpool · CWE-366 | High8.1 | — | 0.5% | Jan 17, 2023 |
32Monitor | CVE-2026-25687No exploit | ZCC race condition in ZPA tunnel handlerzscaler · client connector · CWE-366 | High8.1 | — | 0.4% | Sep 14, 2026 |
31Monitor | CVE-2026-46181No exploit | RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()linux · linux kernel · CWE-366 | High7.8 | — | 0.1% | May 28, 2026 |
29Monitor | CVE-2026-86247No exploit | Apache Tomcat Native: Client certificate requirements can be down-gradedapache software foundation · apache tomcat native · CWE-366 | High7.4 | — | 0.2% | Sep 23, 2026 |
28Monitor | CVE-2023-6546Proof of concept | Kernel: gsm multiplexing race condition leads to privilege escalationlinux · linux kernel · CWE-366 | High7.0 | — | 0.7% | Dec 21, 2023 |
28Monitor | CVE-2022-1729No exploit | A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges.linux · linux kernel · CWE-366 | High7.0 | — | 0.3% | Sep 1, 2022 |
28Monitor | CVE-2024-10630No exploit | A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the applicatiivanti · application control · CWE-366 | High7.0 | — | 0.2% | Jan 14, 2025 |
24Monitor | CVE-2026-3904No exploit | Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under hgnu · glibc · CWE-366 | Medium6.2 | — | 0.2% | Mar 11, 2026 |
23Monitor | CVE-2020-1629No exploit | Junos OS: A race condition vulnerability may cause RPD daemon to crash when processing a BGP NOTIFICATION message.juniper · junos · CWE-366 | Medium5.9 | — | 0.7% | Apr 8, 2020 |
23Monitor | CVE-2023-4127No exploit | Race Condition within a Thread in answerdev/answeranswer · answer · CWE-366 | Medium5.9 | — | 0.5% | Aug 3, 2023 |
23Monitor | CVE-2026-23684No exploit | Race condition vulnerability in SAP Commerce Cloudsap · commerce cloud · CWE-366 | Medium5.9 | — | 0.2% | Feb 10, 2026 |
18Monitor | CVE-2023-4732No exploit | Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.hlinux · linux kernel · CWE-366 | Medium4.7 | — | 0.2% | Oct 3, 2023 |
17Monitor | CVE-2023-3218No exploit | Race Condition within a Thread in it-novum/openitcockpitit-novum · openitcockpit · CWE-366 | Medium4.4 | — | 0.5% | Jun 13, 2023 |
12Monitor | CVE-2024-2032No exploit | Race Condition Vulnerability in zenml-io/zenmlzenml · zenml · CWE-366 | Low3.1 | — | 0.3% | Jun 6, 2024 |
12Monitor | CVE-2026-22819No exploit | Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.tsoutray · outray · CWE-366 | Low3.1 | — | 0.2% | Jan 14, 2026 |
10Monitor | GHSA-mc8h-8q98-g5hrNo exploit | Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_allcrates.io · remove_dir_all · CWE-366 | Low2.5 | — | — | Feb 24, 2023 |
- CVE-2025-5814339Monitor
Mutiple vulnerabilities in the Viridian interface
CriticalCVSS 9.8No exploitEPSS 0%xen · xenSep 11, 2025
- CVE-2025-3111534Monitor
XZ has a heap-use-after-free bug in threaded .xz decoder
HighCVSS 8.7No exploitEPSS 1%tukaani-project · xzApr 3, 2025
- CVE-2021-2656933Monitor
Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows r
HighCVSS 8.1No exploitEPSS 2%synology · diskstation managerMar 12, 2021
- CVE-2015-1006732Monitor
oznetmaster SSharpSmartThreadPool SmartThreadPool.cs race condition
HighCVSS 8.1No exploitEPSS 1%ssharpsmartthreadpool project · ssharpsmartthreadpoolJan 17, 2023
- CVE-2026-2568732Monitor
ZCC race condition in ZPA tunnel handler
HighCVSS 8.1No exploitEPSS 0%zscaler · client connectorSep 14, 2026
- CVE-2026-4618131Monitor
RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
HighCVSS 7.8No exploitEPSS 0%linux · linux kernelMay 28, 2026
- CVE-2026-8624729Monitor
Apache Tomcat Native: Client certificate requirements can be down-graded
HighCVSS 7.4No exploitEPSS 0%apache software foundation · apache tomcat nativeSep 23, 2026
- CVE-2023-654628Monitor
Kernel: gsm multiplexing race condition leads to privilege escalation
HighCVSS 7.0Proof of conceptEPSS 1%linux · linux kernelDec 21, 2023
- CVE-2022-172928Monitor
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges.
HighCVSS 7.0No exploitEPSS 0%linux · linux kernelSep 1, 2022
- CVE-2024-1063028Monitor
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the applicati
HighCVSS 7.0No exploitEPSS 0%ivanti · application controlJan 14, 2025
- CVE-2026-390424Monitor
Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under h
MediumCVSS 6.2No exploitEPSS 0%gnu · glibcMar 11, 2026
- CVE-2020-162923Monitor
Junos OS: A race condition vulnerability may cause RPD daemon to crash when processing a BGP NOTIFICATION message.
MediumCVSS 5.9No exploitEPSS 1%juniper · junosApr 8, 2020
- CVE-2023-412723Monitor
Race Condition within a Thread in answerdev/answer
MediumCVSS 5.9No exploitEPSS 0%answer · answerAug 3, 2023
- CVE-2026-2368423Monitor
Race condition vulnerability in SAP Commerce Cloud
MediumCVSS 5.9No exploitEPSS 0%sap · commerce cloudFeb 10, 2026
- CVE-2023-473218Monitor
Kernel: race between task migrating pages and another task calling exit_mmap to release those same pages getting invalid opcode bug in include/linux/swapops.h
MediumCVSS 4.7No exploitEPSS 0%linux · linux kernelOct 3, 2023
- CVE-2023-321817Monitor
Race Condition within a Thread in it-novum/openitcockpit
MediumCVSS 4.4No exploitEPSS 0%it-novum · openitcockpitJun 13, 2023
- CVE-2024-203212Monitor
Race Condition Vulnerability in zenml-io/zenml
LowCVSS 3.1No exploitEPSS 0%zenml · zenmlJun 6, 2024
- CVE-2026-2281912Monitor
Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts
LowCVSS 3.1No exploitEPSS 0%outray · outrayJan 14, 2026
- GHSA-mc8h-8q98-g5hr10Monitor
Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
LowCVSS 2.5No exploitcrates.io · remove_dir_allFeb 24, 2023