Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 314/1469
7.8
CVE-2026-32090

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered A

7.8
CVE-2026-32089

Use after free in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-32087

Heap-based buffer overflow in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges

7.0
CVE-2026-32086

Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Servic

7.0
CVE-2026-32083

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allo

7.0
CVE-2026-32082

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allo

7.0
CVE-2026-32080

Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32078

Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32077

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele

7.8
CVE-2026-32076

Out-of-bounds read in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-32075

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges

7.8
CVE-2026-32074

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-32073

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.5
CVE-2026-32071

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker t

7.0
CVE-2026-32070

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-32069

Double free in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-32068

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allo

7.0
CVE-2026-27929

Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges l

8.7
CVE-2026-27928

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

7.8
CVE-2026-27927

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File Sy

7.0
CVE-2026-27926

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini

7.8
CVE-2026-27924

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-27923

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-27922

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-27921

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an

7.8
CVE-2026-27920

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele

7.8
CVE-2026-27919

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to ele

7.8
CVE-2026-27918

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an a

7.0
CVE-2026-27917

Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate priv

7.8
CVE-2026-27916

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges

7.8
CVE-2026-27915

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges

7.8
CVE-2026-27914

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

7.7
CVE-2026-27913

Improper input validation in Windows BitLocker allows an unauthorized attacker to bypass a security feature locally.

8.0
CVE-2026-27912

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

7.8
CVE-2026-27911

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Co

7.8
CVE-2026-27910

Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevat

7.8
CVE-2026-27909

Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-27908

Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-27907

Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate pri

7.8
CVE-2026-26184

Buffer over-read in Windows Projected File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-26183

Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

7.0
CVE-2026-26182

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-26181

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-26180

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-26179

Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-26178

Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate pri

7.0
CVE-2026-26177

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.8
CVE-2026-26176

Heap-based buffer overflow in Windows Client Side Caching driver (csc.sys) allows an authorized attacker to elevate priv

7.0
CVE-2026-26174

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Ser

7.0
CVE-2026-26173

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started