Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a networ
Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute co
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService all
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
Reliance on untrusted inputs in a security decision in Windows Kerberos allows an authorized attacker to elevate privile
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate pri
Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
Time-of-check time-of-use (toctou) race condition in Windows Ancillary Function Driver for WinSock allows an authorized
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Inter
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges
Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to
Time-of-check time-of-use (toctou) race condition in Windows Installer allows an authorized attacker to elevate privileg
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to
Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate
Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate priv
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Objec
Incorrect privilege assignment in Windows Hello allows an unauthorized attacker to perform tampering locally.
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a ne
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent
A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specia
A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration d
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of refe
An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated ne
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerabi
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso
Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissio
In Eptura Archibus 2024.03.01.109, the "Run script" and "Server File" components of the "Database Update Wizard" are vul
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS
A path traversal vulnerability in NETGEAR WiFi range extenders allows an attacker with LAN authentication to access the
An insufficient authentication vulnerability in NETGEAR WiFi range extenders allows a network adjacent attacker with Wi
An insufficient input validation vulnerability in the NETGEAR XR1000v2 allows attackers connected to the router's LAN t
An authentication bypass vulnerability in NETGEAR Orbi devices allows users connected to the local network to access th
An insufficient input validation vulnerability in NETGEAR Orbi devices' DHCPv6 functionality allows network adjacent at
An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers connected to the router's LAN t
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: Fix out-of-bounds array a
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: 8192cu: fix tid out of range in rtl9
In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix potential UAF in xe_oa_add_config_io
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_sta
In the Linux kernel, the following vulnerability has been resolved: team: fix check for port enabled in team_queue_over
In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file reference leak in nfsd4_add_rda
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started