Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 313/1469
8.0
CVE-2026-33826

Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent net

7.8
CVE-2026-33825 KEV

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges loc

8.8
CVE-2026-33120

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

7.5
CVE-2026-33116

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized att

8.4
CVE-2026-33115

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.4
CVE-2026-33114

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2026-33104

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

7.8
CVE-2026-33101

Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-33100

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-33099

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-33098

Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges local

7.5
CVE-2026-33096

Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.

7.8
CVE-2026-33095

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.8
CVE-2026-32225

Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a networ

7.0
CVE-2026-32224

Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32222

Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

8.4
CVE-2026-32221

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.

7.0
CVE-2026-32219

Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.5
CVE-2026-32203

Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.

7.8
CVE-2026-32200

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-32199

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-32198

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-32197

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.0
CVE-2026-32195

Stack-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32192

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

8.4
CVE-2026-32190

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-32189

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.1
CVE-2026-32188

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2026-32184

Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elev

7.8
CVE-2026-32183

Improper neutralization of special elements used in a command ('command injection') in Windows Snipping Tool allows an u

7.5
CVE-2026-32178

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

8.8
CVE-2026-32171

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a netw

7.8
CVE-2026-32168

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32165

Use after free in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32164

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Co

7.8
CVE-2026-32163

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Co

8.4
CVE-2026-32162

Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate priv

7.8
CVE-2026-32160

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-32159

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-32158

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

8.8
CVE-2026-32157

Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.4
CVE-2026-32156

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code loc

7.8
CVE-2026-32155

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32154

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32153

Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32152

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-32150

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic

7.3
CVE-2026-32149

Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally.

7.0
CVE-2026-32093

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic

8.4
CVE-2026-32091

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started