CWE-567: Unsynchronized Access to Shared Data in a Multithreaded Context
The product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes.
10 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-48908 — Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerabili
- CVE-2026-48708 — OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
- CVE-2026-79973 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79969 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79962 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-73632 — Apache Struts: Shared serialization state in the JSON plugin
- CVE-2026-73631 — Apache Struts: Shared parsing state in the JSON plugin
Recently published
- CVE-2026-79962 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79969 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79973 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-73632 — Apache Struts: Shared serialization state in the JSON plugin
- CVE-2026-73631 — Apache Struts: Shared parsing state in the JSON plugin
- CVE-2026-48708 — OliveTin has a Concurrent Template Parsing Race Condition which Leads to Cross-Request Command Contamination
- CVE-2025-48908 — Ability Auto Startup service vulnerability in the foundation process Impact: Successful exploitation of this vulnerabili