Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges loc
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a
Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.
Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an au
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a ne
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute
Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate
Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute cod
Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca
Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges local
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started