Cyber Resilience

CWE · MITRE source

CWE-820Missing Synchronization

Abstraction: Base · CVEs in our corpus: 15

The product utilizes a shared resource in a concurrent manner but does not attempt to synchronize access to the resource.

If access to a shared resource is not synchronized, then the resource may not be in a state that is expected by the product. This might lead to unexpected or insecure behaviors, especially if an attacker can influence the shared resource.

Last updated: 21 August 2026 14:15 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-47154 6.49.00.00662025-05-01
CVE-2023-2801 6.07.50.00752023-06-06
CVE-2024-49114 6.07.80.00742024-12-12
CVE-2026-53277 5.98.80.00112026-06-25
CVE-2025-1445 5.87.50.00322025-03-25
CVE-2026-53153 5.57.80.00102026-06-25
CVE-2022-50238 5.47.40.00242025-09-08
CVE-2025-49751 5.16.80.00462025-08-12
CVE-2026-22163 5.17.80.00082026-03-20
CVE-2025-47999 5.06.80.00392025-07-08
CVE-2026-44318 5.06.50.00272026-05-27
CVE-2023-45084 4.97.00.00222023-12-05
CVE-2024-30387 4.96.50.00212024-04-12
CVE-2026-706374.55.90.00232026-08-06
CVE-2026-570294.05.30.00122026-07-09