Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 221/1469
7.8
CVE-2026-42983

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

8.1
CVE-2026-42981

Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code ov

7.8
CVE-2026-42980

Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges local

7.8
CVE-2026-42979

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-42978

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-42977

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

8.1
CVE-2026-42974

Integer overflow or wraparound in Windows Performance Monitor allows an unauthorized attacker to execute code over a net

7.8
CVE-2026-42916

Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-42913

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all

7.0
CVE-2026-42912

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service

7.0
CVE-2026-42911

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-42910

Out-of-bounds write in Windows Hotpatch Monitoring Service allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-42909

Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client all

7.5
CVE-2026-42908

Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2026-42905

Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-42902

Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-42837

Out-of-bounds read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges lo

7.0
CVE-2026-42836

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic

8.1
CVE-2026-42835

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams fo

7.8
CVE-2026-42829

Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature l

7.8
CVE-2026-42828

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges loca

7.5
CVE-2026-42765

Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the who

7.5
CVE-2026-42764

Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenS

7.5
CVE-2026-42570

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the

7.5
CVE-2026-42567

Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the S

7.0
CVE-2026-41108

Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.

8.4
CVE-2026-41098

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an autho

7.8
CVE-2026-41092

Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40409

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

7.8
CVE-2026-40404

Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

7.5
CVE-2026-40376

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

8.8
CVE-2026-40371

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized

7.0
CVE-2026-34335

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.5
CVE-2026-34183

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P

7.4
CVE-2026-34181

Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base

7.5
CVE-2026-34180

Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes

7.8
CVE-2026-33828

Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-32193

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all

7.3
CVE-2026-24181

NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes

7.3
CVE-2026-24180

NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes

7.8
CVE-2026-22926

Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.

8.0
CVE-2026-0419

Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u

8.0
CVE-2026-0411

An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected

8.1
CVE-2026-49948

Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s

8.1
CVE-2026-24065

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile

7.8
CVE-2026-24064

Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC

7.2
CVE-2026-10727

An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut

7.8
CVE-2026-52907

In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change

7.7
CVE-2026-52906

In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep

8.0
CVE-2026-46332

In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started