The product contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock.
Volume of CVEs assigned to CWE-833 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44579HIGH Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feat | May 13, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-10647MEDIUM The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue() in its ethernet transmit callback cdc_ncm_send(). When the | Jun 29, 2026 | 5.3 | 28 | NO | NO |
CVE-2024-48077HIGH NanoMQ v0.22.7 is vulnerable to Denial of Service (DoS) due to improper resource throttling. A crafted sequence of requests causes the recv-q queue to saturate, leading to the rapi | Jan 15, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-10150HIGH Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects
smartLink HW-PN: from 1.02 through 1.03
smartLink H | Oct 28, 2025 | 8.7 | 27 | NO | NO |
CVE-2021-1622HIGH A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cau | Sep 23, 2021 | 8.6 | 27 | NO | NO |
CVE-2025-59463HIGH An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers. | Oct 27, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54796HIGH Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the | Aug 2, 2025 | 7.5 | 25 | NO | NO |
CVE-2026-47334MEDIUM Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivi | May 28, 2026 | 5.5 | 24 | NO | NO |
CVE-2025-36010HIGH IBM Db2 for Linux 12.1.0, 12.1.1, and 12.1.2
could allow an unauthenticated user to cause a denial of service due to executable segments that are waiting for each other to releas | Jul 29, 2025 | 7.5 | 24 | NO | NO |
CVE-2022-43767HIGH A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC | Apr 11, 2023 | 7.5 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.