Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.
Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.
Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privi
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locall
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c
InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c
InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in
InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in a
InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in a
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Devi
Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 w
NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of
NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data cre
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev
Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications ma
Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev
Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escala
Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may al
Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl
Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicat
NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attack
NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker m
Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 with
Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network
Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router)
Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to
System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege e
Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption a
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder
Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thu
Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5,
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunde
Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Fir
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR
Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 11
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticate
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started