Threats Tagged 'cwe-362'
View all threats tagged with 'cwe-362'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-362'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-9030: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization in TP-Link Systems Inc. Archer A6 v4CVE-2026-9030 0 CVE-2026-9030 is a denial-of-service vulnerability in the httpd service of TP-Link Systems Inc. Archer A6 v4. It arises from improper synchronization in handling asynchronous systool instructions, which can cause the httpd process or device management service to crash. Exploitation may lead to temporary loss of access to the web management interface or device reboot. Join the discussion | CVE Database V5 | 08/07/2026, 20:38:35 UTC Added: 08/07/2026, 20:56:45 UTC |
CVE-2026-70640: CWE-476 NULL Pointer Dereference in ggml-org llama.cppCVE-2026-70640 0 llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijack the vtable pointer at offset +0x30, causing llama_batch_allocr::clear() to dereference arbitrary memory and achieve remote code execution. Join the discussion | CVE Database V5 | 08/06/2026, 15:38:22 UTC Added: 08/06/2026, 22:13:33 UTC |
CVE-2026-43631: CWE-416 Use After Free in ggml-org llama.cppCVE-2026-43631 0 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-seconds feature is enabled, allowing unauthenticated remote attackers to execute arbitrary code. Attackers can trigger the vulnerability by sending requests to affected endpoints while the server transitions to sleep mode, causing concurrent worker threads to dereference a freed vocab pointer that can be reclaimed with attacker-controlled data to achieve remote code execution. Join the discussion | CVE Database V5 | 08/07/2026, 00:31:18 UTC Added: 08/06/2026, 22:13:22 UTC |
CVE-2026-48154: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in pilinux gorestCVE-2026-48154 0 GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from and write to this map concurrently, and because Go's runtime treats unsynchronized concurrent map access as an unrecoverable fatal error, an attacker can repeatedly trigger this condition to crash the process on demand. This results in high, repeatable availability impact with no confidentiality or integrity consequences. This issue has been fixed in version 1.12.2. Join the discussion | CVE Database V5 | 08/04/2026, 19:45:51 UTC Added: 08/04/2026, 20:12:01 UTC |
CVE-2026-47620: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in NVIDIA DynamoCVE-2026-47620 0 NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service. Join the discussion | CVE Database V5 | 08/04/2026, 17:32:36 UTC Added: 08/04/2026, 17:57:22 UTC |
CVE-2025-15630: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization in TP-Link Systems Inc. Omada GatewaysCVE-2025-15630 0 A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of provisioning information intended for a legitimate device. Join the discussion | CVE Database V5 | 08/03/2026, 17:51:06 UTC Added: 08/03/2026, 18:33:33 UTC |
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. (CVE-2026-44102)CVE-2026-44102 0 An unauthenticated remote attacker can cause a firmware update download via the OCPP backend by supplying an invalid firmware file. The invalid file remains accessible temporarily due to improper locking during cleanup. This vulnerability is related to a race condition (CWE-362). No patch or remediation details are currently available. Join the discussion | GCVE Database | 07/30/2026, 09:31:17 UTC Added: 07/30/2026, 15:50:19 UTC |
CVE-2026-17841: Race in Google ChromeCVE-2026-17841 0 Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) Join the discussion | GCVE Database | 07/30/2026, 00:19:36 UTC Added: 07/30/2026, 05:45:59 UTC |
CVE-2026-16727: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) in ASUS Armoury CrateCVE-2026-16727 0 Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information. Join the discussion | GCVE Database | 07/30/2026, 02:00:07 UTC Added: 07/30/2026, 05:45:48 UTC |
CVE-2026-16727: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization (‘Race Condition’) in ASUS Armoury CrateCVE-2026-16727 0 A race condition vulnerability (CWE-362) in ASUS Armoury Crate version 5.4.1 allows a local user to execute arbitrary code with elevated privileges by exploiting improper synchronization during concurrent execution involving shared resources. This flaw enables privilege escalation without requiring user interaction. The vulnerability has a high severity rating with a CVSS 4.0 score of 7.3. No official patch or remediation guidance has been provided yet by ASUS. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 07/30/2026, 02:00:07 UTC Added: 07/30/2026, 02:07:50 UTC |
Showing 1 to 10 of 75 results