Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-362

MITRE ↗

CWE-362

50
CRITICAL
1,207
HIGH
833
MEDIUM
77
LOW
2,192 CVEs · Page 8/44
5.9
CVE-2026-22548

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con

5.9
CVE-2026-23684

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car

5.9
CVE-2026-28545

Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av

5.9
CVE-2026-40178

ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a

5.9
CVE-2026-32226

Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an

5.9
CVE-2026-43930

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76

5.9
CVE-2026-47741

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the

5.9
CVE-2026-57030

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packe

5.9
CVE-2026-56649

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Syst

5.9
CVE-2026-45712

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat

5.9
CVE-2025-15630

A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t

5.9
CVE-2026-48154

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri

5.9
CVE-2026-50139

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit

5.9
CVE-2026-76393

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe

5.9
CVE-2025-62300

HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can

5.8
CVE-2026-48982

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when upda

5.8
CVE-2026-61079

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.

5.7
CVE-2026-48066

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a

5.5
CVE-2026-28996

A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26

5.4
CVE-2026-40155

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro

5.4
CVE-2025-15546

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy s

5.4
CVE-2026-15995

IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain inc

5.3
CVE-2026-22701

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability

5.3
CVE-2026-20927

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows

5.3
CVE-2025-31944

Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Author

5.3
CVE-2026-32700

Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Con

5.3
CVE-2026-34368

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p

5.3
CVE-2026-34363

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

5.3
CVE-2026-5890

Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive info

5.3
CVE-2026-7960

Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer proces

5.3
CVE-2026-11145

Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin da

5.3
CVE-2026-13874

Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i

5.3
CVE-2026-16082

A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun

5.3
CVE-2026-55219

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the

5.3
CVE-2026-44102

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f

5.1
CVE-2025-52515

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,

5.1
CVE-2025-68961

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner

5.1
CVE-2025-68962

Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner

5.1
CVE-2026-28834

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1

5.1
CVE-2026-28888

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1

5.0
CVE-2026-39880

Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H

5.0
CVE-2026-7724

A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function va

5.0
CVE-2026-16208

A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottl

4.8
CVE-2025-66803

Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d

4.8
CVE-2026-24040

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes

4.8
CVE-2026-44443

Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level varia

4.7
CVE-2026-22986

In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two

4.7
CVE-2026-23071

In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave ro

4.7
CVE-2026-23110

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final co

4.7
CVE-2026-23115

In the Linux kernel, the following vulnerability has been resolved: serial: Fix not set tty->port race condition Rever

Frequently Asked Questions

What is CWE-362?

CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-362?

There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.

How can I protect against CWE-362 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.

Detect CWE-362 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.

Get Started