Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 527/1469
7.5
CVE-2025-60536

An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Servi

7.3
CVE-2025-57618

A path traversal vulnerability in FastX3 thru 3.3.67 allows an unauthenticated attacker to read arbitrary files on the s

8.4
CVE-2025-23356

NVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might

7.3
CVE-2025-11736

A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit

7.3
CVE-2025-60535

A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to e

7.5
CVE-2025-59502

Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over

7.0
CVE-2025-59497

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny

7.8
CVE-2025-59494

Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-59295

Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.

8.2
CVE-2025-59292

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate

8.2
CVE-2025-59291

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate

7.8
CVE-2025-59290

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59289

Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59285

Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-59282

Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows

7.8
CVE-2025-59281

Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to

7.8
CVE-2025-59278

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat

7.8
CVE-2025-59277

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat

7.8
CVE-2025-59275

Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevat

7.0
CVE-2025-59261

Time-of-check time-of-use (toctou) race condition in Microsoft Graphics Component allows an authorized attacker to eleva

7.8
CVE-2025-59255

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-59254

Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

8.1
CVE-2025-59250

Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a netwo

8.8
CVE-2025-59249

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

7.5
CVE-2025-59248

Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a networ

7.8
CVE-2025-59243

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59242

Heap-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pri

7.8
CVE-2025-59241

Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allow

7.8
CVE-2025-59238

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-59237

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

8.4
CVE-2025-59236

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-59235

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-59234

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59233

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.1
CVE-2025-59232

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-59231

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2025-59230 KEV

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges

8.8
CVE-2025-59228

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7.8
CVE-2025-59227

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59226

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59225

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59224

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59223

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-59222

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.0
CVE-2025-59221

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-59213

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager

7.4
CVE-2025-59210

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

7.1
CVE-2025-59208

Out-of-bounds read in Windows MapUrlToZone allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2025-59207

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.4
CVE-2025-59206

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started