CWE-820: Missing Synchronization
The product utilizes a shared resource in a concurrent manner but does not attempt to synchronize access to the resource.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-47154 — LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-a
- CVE-2025-1445 — A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiat
- CVE-2026-22163 — GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
- CVE-2026-70637 — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
- CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
- CVE-2026-57029 — Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
Recently published
- CVE-2026-70637 — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
- CVE-2026-57029 — Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
- CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
- CVE-2026-22163 — GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
- CVE-2025-47154 — LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-a
- CVE-2025-1445 — A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiat