Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv
Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges l
Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate
Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows
Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locall
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an a
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to e
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate priv
Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started