Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 142/1469
8.8
CVE-2026-47300

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges

7.5
CVE-2026-45305

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

7.5
CVE-2026-45304

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

7.5
CVE-2026-45133

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

8.2
CVE-2026-45075

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.

7.3
CVE-2026-45073

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4

8.6
CVE-2026-15720

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler

7.1
CVE-2026-15641

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authen

7.5
CVE-2026-15637

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.2

7.0
CVE-2026-58637

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58634

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58633

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58632

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-58629

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58628

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networki

7.5
CVE-2026-58627

Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.

8.8
CVE-2026-58626

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.

7.0
CVE-2026-58619

Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

8.1
CVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a ne

7.8
CVE-2026-58613

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-58594

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.

7.0
CVE-2026-58544

Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58542

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-58541

Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate pr

7.8
CVE-2026-58540

Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58538

Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-58537

Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges loc

7.8
CVE-2026-58536

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-58534

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges lo

7.8
CVE-2026-58532

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-58531

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an aut

7.8
CVE-2026-58530

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local

7.1
CVE-2026-58529

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information

7.8
CVE-2026-58527

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

8.8
CVE-2026-58277

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network

7.8
CVE-2026-57968

Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-57108

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny servi

8.8
CVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass

7.1
CVE-2026-57101

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an una

7.8
CVE-2026-57096

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate

8.8
CVE-2026-57094

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a

7.0
CVE-2026-57093

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-57091

Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-57090

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a

7.5
CVE-2026-57089

Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute co

7.8
CVE-2026-57088

Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally

8.8
CVE-2026-57087

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a

7.8
CVE-2026-56650

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-56648

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevat

8.8
CVE-2026-56647

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started