Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-362

MITRE ↗

CWE-362

50
CRITICAL
1,207
HIGH
833
MEDIUM
77
LOW
2,192 CVEs · Page 24/44
8.8
CVE-2022-2742

Use after free in Exosphere in Google Chrome on Chrome OS and Lacros prior to 104.0.5112.79 allowed a remote attacker wh

8.1
CVE-2023-21535

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

8.1
CVE-2023-21546

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

8.1
CVE-2023-21679

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability

8.1
CVE-2021-36532

Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt pa

8.1
CVE-2022-42951

An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. Duri

8.1
CVE-2023-23404

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-21712

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-24903

Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

8.1
CVE-2023-33170

ASP.NET and Visual Studio Security Feature Bypass Vulnerability

8.1
CVE-2023-32257

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t

8.1
CVE-2023-32258

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t

8.1
CVE-2023-41915

OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race con

8.1
CVE-2023-38166

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41765

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41767

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41768

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41769

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41770

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41771

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41773

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-41774

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

8.1
CVE-2023-20571

A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage C

8.1
CVE-2023-40077

In multiple functions of MetaDataBase.cpp, there is a possible UAF write due to a race condition. This could lead to rem

7.8
CVE-2022-31645

Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary

7.8
CVE-2023-35362

Windows Clip Service Elevation of Privilege Vulnerability

7.5
CVE-2023-22499

Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Multi-threaded programs were able to

7.5
CVE-2023-24042

A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A han

7.5
CVE-2022-32764

Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to poten

7.5
CVE-2022-48221

An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. Multiple MSI's get executed out of a standard-user wri

7.5
CVE-2023-28232

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

7.5
CVE-2023-1285

Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit se

7.5
CVE-2023-33974

RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process

7.5
CVE-2023-29537

Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-contro

7.5
CVE-2023-35309

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

7.5
CVE-2023-36884 KEV

Windows Search Remote Code Execution Vulnerability

7.5
CVE-2023-34438

Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privil

7.5
CVE-2023-49786

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1,

7.3
CVE-2023-47111

ZITADEL provides identity infrastructure. ZITADEL provides administrators the possibility to define a `Lockout Policy` w

7.1
CVE-2023-23407

Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability

7.1
CVE-2023-46132

Hyperledger Fabric is an open source permissioned distributed ledger framework. Combining two molecules to one another,

7.0
CVE-2023-21542

Windows Installer Elevation of Privilege Vulnerability

7.0
CVE-2023-21733

Windows Bind Filter Driver Elevation of Privilege Vulnerability

7.0
CVE-2023-21771

Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability

7.0
CVE-2020-19824

An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parame

7.0
CVE-2023-23393

Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability

7.0
CVE-2023-24861

Windows Graphics Component Elevation of Privilege Vulnerability

7.0
CVE-2023-28144

KDAB Hotspot 1.3.x and 1.4.x through 1.4.1, in a non-default configuration, allows privilege escalation because of race

7.0
CVE-2023-28273

Windows Clip Service Elevation of Privilege Vulnerability

7.0
CVE-2023-26980

PAX Technology PAX A920 Pro PayDroid 8.1suffers from a Race Condition vulnerability, which allows attackers to bypass th

Frequently Asked Questions

What is CWE-362?

CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-362?

There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.

How can I protect against CWE-362 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.

Detect CWE-362 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.

Get Started