When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with con
A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a car
Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av
ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the
A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packe
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File Syst
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?dat
A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with t
GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit
In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by anothe
HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when upda
Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro
The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy s
IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain inc
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Author
Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Con
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive info
Race in Speech in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer proces
Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin da
Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive i
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the
An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulner
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 1
Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H
A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function va
A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottl
Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d
jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, the addJS method in the jspdf Node.js build utilizes
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level varia
In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two
In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave ro
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final co
In the Linux kernel, the following vulnerability has been resolved: serial: Fix not set tty->port race condition Rever
Frequently Asked Questions
What is CWE-362?
CWE-362 (CWE-362) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-362?
There are 2,933 CVE records associated with CWE-362 in our database. Of these, 50 are critical severity, 1207 are high severity, and 833 are medium severity.
How can I protect against CWE-362 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-362 using AI-powered security agents.
Detect CWE-362 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-362 vulnerabilities across your infrastructure.
Get Started