If two threads of execution use a resource simultaneously, there exists the possibility that resources may be used while invalid, in turn making the state of execution undefined.
Volume of CVEs assigned to CWE-366 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58143CRITICAL [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are multiple issues related to the handling | Sep 11, 2025 | 9.8 | 32 | NO | NO |
CVE-2026-46181HIGH In the Linux kernel, the following vulnerability has been resolved:
RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
Sashiko points out the radix_tree itself is RCU safe, but no | May 28, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-23666HIGH Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | Apr 14, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-31115HIGH XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where inval | Apr 3, 2025 | 8.7 | 29 | NO | NO |
CVE-2024-6778HIGH Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page | Jul 16, 2024 | 7.5 | 27 | NO | NO |
CVE-2015-10067HIGH A vulnerability was found in oznetmaster SSharpSmartThreadPool. It has been classified as problematic. This affects an unknown part of the file SSharpSmartThreadPool/SmartThreadPoo | Jan 18, 2023 | 8.1 | 26 | NO | NO |
CVE-2021-26569HIGH Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary cod | Mar 12, 2021 | 8.1 | 26 | NO | NO |
CVE-2026-3904MEDIUM Calling NSS-backed functions that support caching via nscd may call the
nscd client side code and in the GNU C Library version 2.36 under high
load on x86_64 systems, the client | Mar 11, 2026 | 6.2 | 25 | NO | NO |
CVE-2022-1729HIGH A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit pri | Sep 1, 2022 | 7.0 | 24 | NO | NO |
CVE-2023-4127MEDIUM Race Condition within a Thread in GitHub repository answerdev/answer prior to v1.1.1. | Aug 3, 2023 | 5.9 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.