Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

2,497
Assigned CVEs
31st
Commonality Rank
6.3
Avg CVSS
0.4%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-362 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 1999
26 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

2,497 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-36884HIGH
Windows Search Remote Code Execution Vulnerability
Jul 11, 20237.596YESNO
CVE-2016-5195HIGH
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature
Nov 10, 20167.095YESYES
CVE-2024-6387HIGH
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
CVE-2018-15473MEDIUM
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has be
Aug 17, 20185.386NOYES
CVE-2025-62215HIGH
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Nov 11, 20257.080YESYES
CVE-2021-21166HIGH
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Mar 9, 20218.878YESNO
CVE-2014-0196MEDIUM
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users
May 7, 20145.578YESYES
CVE-2022-26904HIGH
Windows User Profile Service Elevation of Privilege Vulnerability
Apr 15, 20227.076YESYES
CVE-2014-0226MEDIUM
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtai
Jul 20, 20146.875NOYES
CVE-2024-27983HIGH
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave so
Apr 9, 20248.274NONO
View all 2,497 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
25%
10%
4.0-4.9
11%
19%
5.0-5.9
13%
16%
6.0-6.9
35%
26%
7.0-7.9
10%
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
11 CVEs
0.4% of CVEs· 84th percentile
Metasploit
11 CVEs
0.4% of CVEs· 82nd percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
81 CVEs
3.2% of CVEs· 93rd percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products