Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code ov
Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges local
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification
Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a net
Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges lo
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams fo
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature l
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca
Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the who
Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenS
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the S
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an autho
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P
Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base
Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected
Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut
In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change
In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep
In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started