Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 588/1469
7.8
CVE-2025-53725

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke

7.8
CVE-2025-53724

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke

7.8
CVE-2025-53723

Numeric truncation error in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-53722

Uncontrolled resource consumption in Windows Remote Desktop Services allows an unauthorized attacker to deny service ove

7.0
CVE-2025-53721

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

8.0
CVE-2025-53720

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute

7.0
CVE-2025-53718

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.8
CVE-2025-53155

Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-53154

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi

7.8
CVE-2025-53152

Use after free in Desktop Windows Manager allows an authorized attacker to execute code locally.

7.8
CVE-2025-53151

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-53149

Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privile

7.0
CVE-2025-53147

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

8.8
CVE-2025-53145

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker t

8.8
CVE-2025-53144

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker t

8.8
CVE-2025-53143

Access of resource using incompatible type ('type confusion') in Windows Message Queuing allows an authorized attacker t

7.0
CVE-2025-53142

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-53141

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi

7.0
CVE-2025-53140

Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-53137

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

7.0
CVE-2025-53135

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an

7.0
CVE-2025-53134

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio

7.8
CVE-2025-53133

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-53132

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX all

8.8
CVE-2025-53131

Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network.

8.1
CVE-2025-50177

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

7.8
CVE-2025-50176

Access of resource using incompatible type ('type confusion') in Graphics Kernel allows an authorized attacker to execut

7.8
CVE-2025-50173

Weak authentication in Windows Installer allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-50170

Improper handling of insufficient permissions or privileges in Windows Cloud Files Mini Filter Driver allows an authoriz

7.5
CVE-2025-50169

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an una

7.8
CVE-2025-50168

Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to

7.0
CVE-2025-50167

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an

8.0
CVE-2025-50164

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute

8.8
CVE-2025-50163

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

8.0
CVE-2025-50162

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute

7.3
CVE-2025-50161

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

8.0
CVE-2025-50160

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute

7.3
CVE-2025-50159

Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privilege

7.0
CVE-2025-50158

Time-of-check time-of-use (toctou) race condition in Windows NTFS allows an unauthorized attacker to disclose informatio

7.8
CVE-2025-50155

Access of resource using incompatible type ('type confusion') in Windows Push Notifications allows an authorized attacke

7.8
CVE-2025-50153

Use after free in Desktop Windows Manager allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-49762

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Functio

7.8
CVE-2025-49761

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-49759

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

8.8
CVE-2025-49758

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

8.8
CVE-2025-49757

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

8.8
CVE-2025-49712

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne

7.9
CVE-2025-49707

Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.

8.7
CVE-2025-49557

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a

7.5
CVE-2025-49556

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started