The product utilizes a shared resource in a concurrent manner, but it does not correctly synchronize access to the resource.
Volume of CVEs assigned to CWE-821 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-43198CRITICAL In the Linux kernel, the following vulnerability has been resolved:
tcp: fix potential race in tcp_v6_syn_recv_sock()
Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_ | May 6, 2026 | 9.8 | 38 | NO | NO |
CVE-2026-56132MEDIUM In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sha | Jun 19, 2026 | 6.9 | 33 | NO | NO |
CVE-2024-1739CRITICAL lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email add | Apr 16, 2024 | 9.1 | 25 | NO | NO |
CVE-2026-21919MEDIUM An Incorrect Synchronization vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based attacker with low privileges to c | Apr 9, 2026 | 6.5 | 22 | NO | NO |
CVE-2023-5088HIGH A bug in QEMU could cause a guest I/O operation otherwise addressed to an arbitrary disk offset to be targeted to offset 0 instead (potentially overwriting the VM's boot code). Thi | Nov 3, 2023 | 7.0 | 21 | NO | NO |
CVE-2022-1931HIGH Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3. | May 31, 2022 | 8.1 | 21 | NO | NO |
CVE-2024-1902HIGH lunary-ai/lunary is vulnerable to a session reuse attack, allowing a removed user to change the organization name without proper authorization. The vulnerability stems from the lac | Apr 10, 2024 | 7.5 | 19 | NO | NO |
CVE-2024-6657MEDIUM A denial of service may be caused to a single peripheral device in a BLE network when multiple central
devices continuously connect and disconnect to the peripheral. A hard reset | Oct 11, 2024 | 6.5 | 18 | NO | NO |
CVE-2024-5755MEDIUM In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of multiple accounts w | Jun 27, 2024 | 5.3 | 16 | NO | NO |
CVE-2024-58133MEDIUM In chainmaker-go (aka ChainMaker) before 2.4.0, when making frequent updates to a node's configuration file and restarting this node, concurrent writes by logger.go to a map are mi | Apr 6, 2025 | 4.0 | 15 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.