Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 560/1469
7.5
CVE-2025-57061

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via t

7.5
CVE-2025-57059

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule fun

7.5
CVE-2025-57058

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the p

7.5
CVE-2025-57057

Tenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStor

7.8
CVE-2025-55317

Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attack

7.8
CVE-2025-55316

External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-55245

Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileg

7.5
CVE-2025-55243

Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to p

7.3
CVE-2025-55236

Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code local

8.8
CVE-2025-55234

SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited

7.8
CVE-2025-55228

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

8.8
CVE-2025-55227

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized a

7.8
CVE-2025-55224

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

7.0
CVE-2025-55223

Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an

7.5
CVE-2025-54919

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

8.8
CVE-2025-54918

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

7.8
CVE-2025-54916

Stack-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

7.8
CVE-2025-54913

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows UI XAML Maps MapC

7.8
CVE-2025-54912

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

7.3
CVE-2025-54911

Use after free in Windows BitLocker allows an authorized attacker to elevate privileges locally.

8.4
CVE-2025-54910

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54908

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54907

Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54906

Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-54905

Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

7.8
CVE-2025-54904

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54903

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54902

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54900

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54899

Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54898

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.8
CVE-2025-54897

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

7.8
CVE-2025-54896

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-54895

Integer overflow or wraparound in Windows SPNEGO Extended Negotiation allows an authorized attacker to elevate privilege

7.8
CVE-2025-54894

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

8.1
CVE-2025-54709

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.7
CVE-2025-54248

Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an Improper Input Validation vulnerability that c

7.3
CVE-2025-54116

Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-54115

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an

7.0
CVE-2025-54114

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices

8.8
CVE-2025-54113

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

7.0
CVE-2025-54112

Use after free in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-54111

Use after free in Windows UI XAML Phone DatePickerFlyout allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-54110

Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-54108

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Managem

8.8
CVE-2025-54106

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to ex

7.0
CVE-2025-54105

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File

7.4
CVE-2025-54103

Use after free in Windows Management Services allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2025-54102

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

7.0
CVE-2025-54099

Stack-based buffer overflow in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate pr

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started