Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 144/1469
7.3
CVE-2026-55034

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.8
CVE-2026-55033

Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55032

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55031

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55029

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55025

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-55024

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-55022

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

7.3
CVE-2026-55021

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

7.8
CVE-2026-55018

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-55017

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-54131

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-54128

Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-54125

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

7.8
CVE-2026-54124

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.

8.8
CVE-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privile

7.8
CVE-2026-54115

Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50692

Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50689

Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50688

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50687

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.1
CVE-2026-50686

Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute

7.5
CVE-2026-50685

Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.

8.0
CVE-2026-50683

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent n

7.1
CVE-2026-50682

Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

8.2
CVE-2026-50680

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50679

Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges loc

7.8
CVE-2026-50677

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50676

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.0
CVE-2026-50674

Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50673

Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50672

Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50670

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50669

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.8
CVE-2026-50667

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an au

8.8
CVE-2026-50666

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a ne

7.8
CVE-2026-50665

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

7.0
CVE-2026-50658

Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privile

7.8
CVE-2026-50655

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.

7.5
CVE-2026-50647

Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unautho

7.8
CVE-2026-50510

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute

7.8
CVE-2026-50509

Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate

7.5
CVE-2026-50505

Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.

7.0
CVE-2026-50503

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

8.0
CVE-2026-50502

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute cod

7.8
CVE-2026-50501

Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code loca

7.5
CVE-2026-50500

Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.

7.8
CVE-2026-50499

Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges local

7.8
CVE-2026-50498

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

7.5
CVE-2026-50496

Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started