Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 503/1469
7.5
CVE-2025-60704

Missing cryptographic step in Windows Kerberos allows an unauthorized attacker to elevate privileges over a network.

7.8
CVE-2025-60703

Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59515

Use after free in Windows Broadcast DVR User Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59514

Improper privilege management in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally

7.8
CVE-2025-59512

Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privi

7.8
CVE-2025-59511

External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locall

7.0
CVE-2025-59508

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an

7.0
CVE-2025-59507

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an

7.0
CVE-2025-59506

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an

7.8
CVE-2025-59505

Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.

7.3
CVE-2025-59504

Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-59499

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

8.1
CVE-2025-30398

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2025-61832

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could

7.8
CVE-2025-61824

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could

7.8
CVE-2025-61818

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c

7.8
CVE-2025-61817

InCopy versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary c

7.8
CVE-2025-61816

InCopy versions 20.5, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in

7.8
CVE-2025-61815

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in a

7.8
CVE-2025-61814

InDesign Desktop versions 20.5, 19.5.5 and earlier are affected by a Use After Free vulnerability that could result in a

8.2
CVE-2025-35971

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev

7.4
CVE-2025-35967

Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Devi

7.4
CVE-2025-35963

Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 w

8.8
CVE-2025-33186

NVIDIA AIStore contains a vulnerability in AuthN. A successful exploit of this vulnerability might lead to escalation of

7.8
CVE-2025-33178

NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data cre

7.4
CVE-2025-33029

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev

8.8
CVE-2025-33000

Improper input validation for some Intel QuickAssist Technology before version 2.6.0 within Ring 3: User Applications ma

8.2
CVE-2025-32091

Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may

8.2
CVE-2025-30255

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Dev

7.9
CVE-2025-30185

Active debug code for some Intel UEFI reference platforms within Ring 0: Kernel may allow a denial of service and escala

7.8
CVE-2025-27713

Out-of-bounds write for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may al

8.8
CVE-2025-24838

Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl

8.8
CVE-2025-24299

Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applicat

7.8
CVE-2025-23361

NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attack

7.8
CVE-2025-23357

NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker m

7.8
CVE-2025-20010

Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 with

8.8
CVE-2025-12944

Improper input validation in NETGEAR DGN2200v4 (N300 Wireless ADSL2+ Modem Router) allows attackers with direct network

7.5
CVE-2025-12943

Improper certificate validation in firmware update logic in NETGEAR RAX30 (Nighthawk AX5 5-Stream AX2400 WiFi 6 Router)

7.5
CVE-2025-12942

Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to

8.1
CVE-2025-9408

System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege e

8.1
CVE-2025-13027

Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption a

7.5
CVE-2025-13025

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder

8.8
CVE-2025-13020

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thu

8.1
CVE-2025-13019

Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5,

8.1
CVE-2025-13018

Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunde

8.1
CVE-2025-13017

Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR

7.5
CVE-2025-13016

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Fir

8.8
CVE-2025-13014

Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR

7.5
CVE-2025-13012

Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 11

7.1
CVE-2025-10918

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticate

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started