Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 587/1469
7.8
CVE-2025-54217

InCopy versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in

7.8
CVE-2025-54216

InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbit

7.8
CVE-2025-54215

InCopy versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbit

7.8
CVE-2025-54213

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could resul

7.8
CVE-2025-54212

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could

7.8
CVE-2025-54211

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could

7.8
CVE-2025-54210

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could resul

7.8
CVE-2025-54209

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could

7.8
CVE-2025-54208

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could resul

7.8
CVE-2025-54207

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that

7.8
CVE-2025-54206

InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds write vulnerability that could resul

7.8
CVE-2025-54187

Substance3D - Painter versions 11.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-49573

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-49572

Substance3D - Modeler versions 1.22.0 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-49571

Substance3D - Modeler versions 1.22.0 and earlier are affected by an Uncontrolled Search Path Element vulnerability that

7.8
CVE-2025-49570

Photoshop Desktop versions 25.12.3, 26.8 and earlier are affected by an out-of-bounds write vulnerability that could res

7.8
CVE-2025-49561

Animate versions 23.0.12, 24.0.9 and earlier are affected by a Use After Free vulnerability that could result in arbitra

7.8
CVE-2025-49569

Substance3D - Viewer versions 0.25 and earlier are affected by an out-of-bounds write vulnerability that could result in

7.8
CVE-2025-49560

Substance3D - Viewer versions 0.25 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res

7.2
CVE-2025-53744

An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0

8.1
CVE-2025-52970

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.

7.2
CVE-2025-49813

An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in

8.1
CVE-2024-26009

An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.

7.5
CVE-2025-53793

Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2025-53789

Missing authentication for critical function in Windows StateRepository API allows an authorized attacker to elevate pri

7.0
CVE-2025-53788

Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to elevat

8.4
CVE-2025-53784

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.5
CVE-2025-53783

Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.

7.7
CVE-2025-53781

Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to di

7.2
CVE-2025-53779

Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

8.8
CVE-2025-53778

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

7.8
CVE-2025-53773

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio

8.8
CVE-2025-53772

Deserialization of untrusted data in Web Deploy allows an authorized attacker to execute code over a network.

7.8
CVE-2025-53761

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

7.1
CVE-2025-53760

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov

7.8
CVE-2025-53759

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53741

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-53740

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53739

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

7.8
CVE-2025-53738

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53737

Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53735

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53734

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-53733

Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code loca

7.8
CVE-2025-53732

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-53731

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53730

Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-53729

Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-53727

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

7.8
CVE-2025-53726

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started