The product does not lock or does not correctly lock a resource when the product must have exclusive access to the resource.
Volume of CVEs assigned to CWE-413 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32748HIGH Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denia | Mar 26, 2026 | 7.5 | 34 | NO | NO |
CVE-2025-3450CRITICAL An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker t | Oct 7, 2025 | 10.0 | 33 | NO | NO |
CVE-2026-44608MEDIUM NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zon | May 20, 2026 | 5.9 | 26 | NO | NO |
CVE-2025-69198MEDIUM Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocati | Jan 19, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-0003HIGH Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of confidentiality or availability | Nov 24, 2025 | 7.3 | 24 | NO | NO |
CVE-2023-28649HIGH The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate | May 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-20678HIGH A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of se | Apr 15, 2022 | 7.5 | 24 | NO | NO |
CVE-2019-17102HIGH An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware | Jan 27, 2020 | 8.1 | 24 | NO | NO |
CVE-2023-32253MEDIUM A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a denial of service. | Aug 2, 2025 | 5.9 | 22 | NO | NO |
CVE-2022-49737HIGH In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread wit | Mar 16, 2025 | 7.7 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.