Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized a
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an autho
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.
Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to e
Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker
Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker t
Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut
Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileg
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to exec
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges local
Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed
Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager
Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele
Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result
A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. This vulnerability affe
A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. This affects an unkno
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated atta
node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to exe
Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerabilit
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0
A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64
A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue af
Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When ru
A vulnerability classified as critical was found in code-projects Library System 1.0. This vulnerability affects unknown
A vulnerability classified as critical has been found in code-projects Food Distributor Site 1.0. This affects an unknow
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started