Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 220/1469
7.8
CVE-2026-45586

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an

7.5
CVE-2026-45583

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker t

8.8
CVE-2026-45504

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over

8.1
CVE-2026-45503

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network

7.8
CVE-2026-45490

Improper authorization in .NET allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-45487

Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attack

7.8
CVE-2026-45486

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.8
CVE-2026-45484

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ove

8.4
CVE-2026-45482

Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code

7.3
CVE-2026-45481

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

8.2
CVE-2026-45476

Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-45475

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-45474

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-45472

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-45471

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-45469

Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally

8.4
CVE-2026-45463

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-45461

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-45458

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-45457

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-45456

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe

8.8
CVE-2026-45447

Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signatur

7.5
CVE-2026-45445

Issue summary: When an application drives an AES-OCB context through the public EVP_Cipher() one-shot interface, the app

7.8
CVE-2026-44824

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-44823

Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.2
CVE-2026-44822

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2026-44820

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-44819

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.0
CVE-2026-44818

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel al

7.8
CVE-2026-44817

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2026-44813

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-44812

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-44811

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

8.4
CVE-2026-44810

Improper authentication in Windows Cryptographic Services allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2026-44809

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-44808

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-44807

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-44804

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-44803

Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-44802

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-44801

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-44799

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-42993

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.5
CVE-2026-42992

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.8
CVE-2026-42991

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-42989

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate priv

8.1
CVE-2026-42987

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

7.8
CVE-2026-42986

Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-42985

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.0
CVE-2026-42984

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started