Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 146/1469
7.8
CVE-2026-50421

Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows

7.8
CVE-2026-50417

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

7.5
CVE-2026-50414

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

8.8
CVE-2026-50413

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50412

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-50411

Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny serv

7.0
CVE-2026-50410

Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50407

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges l

7.0
CVE-2026-50406

Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50405

Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate

7.0
CVE-2026-50404

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.0
CVE-2026-50403

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

7.8
CVE-2026-50402

Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50400

Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50399

Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50398

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.0
CVE-2026-50397

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50396

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50393

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50392

Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50391

Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50390

Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate

7.8
CVE-2026-50388

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50387

Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50386

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

8.8
CVE-2026-50385

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

8.8
CVE-2026-50382

Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.

7.5
CVE-2026-50379

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an a

7.8
CVE-2026-50378

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows

7.8
CVE-2026-50373

Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locall

7.0
CVE-2026-50372

Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50371

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an a

8.8
CVE-2026-50370

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent netwo

8.8
CVE-2026-50369

Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.

7.5
CVE-2026-50368

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over

7.8
CVE-2026-50367

Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to e

8.0
CVE-2026-50365

Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent networ

7.8
CVE-2026-50363

Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50362

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code local

7.8
CVE-2026-50361

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-50360

Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate priv

7.0
CVE-2026-50359

Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50358

Use after free in Windows Media allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-50357

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

7.5
CVE-2026-50355

Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over

7.8
CVE-2026-50353

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50348

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

7.8
CVE-2026-50347

Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50346

Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-50345

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started