Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 271/1469
7.1
CVE-2026-41102

Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.

7.1
CVE-2026-41101

Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.

7.8
CVE-2026-41095

Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-41094

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker t

7.8
CVE-2026-41088

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

8.8
CVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2026-40420

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40419

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40418

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40417

Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.

8.1
CVE-2026-40415

Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

7.4
CVE-2026-40414

Windows TCP/IP Denial of Service Vulnerability

7.4
CVE-2026-40413

Windows TCP/IP Denial of Service Vulnerability

7.0
CVE-2026-40410

Use after free in Windows SMB Client allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40408

Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40407

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges

7.5
CVE-2026-40406

Use after free in Windows TCP/IP allows an unauthorized attacker to disclose information over a network.

7.5
CVE-2026-40405

Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.

8.8
CVE-2026-40403

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.

7.1
CVE-2026-40401

Windows TCP/IP Denial of Service Vulnerability

7.8
CVE-2026-40399

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an

7.8
CVE-2026-40398

Heap-based buffer overflow in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40397

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges

7.8
CVE-2026-40382

Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40381

Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-40377

Heap-based buffer overflow in Windows Cryptographic Services allows an authorized attacker to elevate privileges locally

8.8
CVE-2026-40370

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

7.8
CVE-2026-40369

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.0
CVE-2026-40368

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.4
CVE-2026-40367

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t

8.4
CVE-2026-40366

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t

8.8
CVE-2026-40365

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.4
CVE-2026-40364

Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker t

8.4
CVE-2026-40363

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-40362

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-40361

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-40360

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2026-40359

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-40358

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

8.8
CVE-2026-40357

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.8
CVE-2026-35439

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.3
CVE-2026-35438

Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2026-35436

Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.

7.3
CVE-2026-35433

Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.

7.5
CVE-2026-35424

Missing release of memory after effective lifetime in Windows Internet Key Exchange (IKE) Protocol allows an unauthorize

7.8
CVE-2026-35421

Heap-based buffer overflow in Windows GDI allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-35420

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-35418

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-35417

Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-35416

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started