Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 502/1469
7.5
CVE-2025-40744

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not

8.8
CVE-2024-32011

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i

7.8
CVE-2024-32010

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i

7.8
CVE-2024-32009

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i

7.8
CVE-2024-32008

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application i

7.8
CVE-2025-61839

Format Plugins versions 1.1.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted fil

7.8
CVE-2025-61838

Format Plugins versions 1.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i

7.8
CVE-2025-61837

Format Plugins versions 1.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i

7.1
CVE-2025-61830

Adobe Pass versions 3.7.3 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could levera

8.0
CVE-2025-62452

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute

8.8
CVE-2025-62222

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat E

8.8
CVE-2025-62220

Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a net

7.0
CVE-2025-62219

Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-62218

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provis

7.0
CVE-2025-62217

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio

7.8
CVE-2025-62216

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-62215 KEV

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an

7.0
CVE-2025-62213

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

8.7
CVE-2025-62211

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (onli

8.7
CVE-2025-62210

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (onli

7.8
CVE-2025-62205

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.0
CVE-2025-62204

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

7.8
CVE-2025-62203

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-62202

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-62201

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62200

Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-62199

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-61836

Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability t

7.8
CVE-2025-61831

Illustrator versions 28.7.10, 29.8.2 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-61829

Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res

7.8
CVE-2025-61828

Illustrator on iPad versions 3.0.9 and earlier are affected by an out-of-bounds write vulnerability that could result in

7.8
CVE-2025-61827

Illustrator on iPad versions 3.0.9 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res

7.8
CVE-2025-61826

Illustrator on iPad versions 3.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability t

7.8
CVE-2025-61820

Illustrator versions 28.7.10, 29.8.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r

7.8
CVE-2025-61819

Photoshop Desktop versions 26.8.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu

7.8
CVE-2025-60727

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-60726

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-60721

Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privilege

7.8
CVE-2025-60720

Buffer over-read in Windows TDX.sys allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-60719

Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate

7.8
CVE-2025-60718

Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-60717

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-60716

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

8.0
CVE-2025-60715

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute

7.8
CVE-2025-60714

Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-60713

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to eleva

7.8
CVE-2025-60710 KEV

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized at

7.8
CVE-2025-60709

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-60707

Use after free in Multimedia Class Scheduler Service (MMCSS) allows an authorized attacker to elevate privileges locally

7.8
CVE-2025-60705

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started