Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 615/1469
7.3
CVE-2025-7198

A vulnerability classified as critical was found in code-projects Jonnys Liquor 1.0. This vulnerability affects unknown

7.3
CVE-2025-7197

A vulnerability classified as critical has been found in code-projects Jonnys Liquor 1.0. This affects an unknown part o

7.8
CVE-2025-6759

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for

8.5
CVE-2025-53547

Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a s

7.8
CVE-2025-49532

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability

7.8
CVE-2025-49531

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that cou

7.8
CVE-2025-49530

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-49529

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an Access of Uninitialized Pointer vulnerability that co

7.8
CVE-2025-49528

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could r

7.8
CVE-2025-49527

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could r

7.8
CVE-2025-49526

Illustrator versions 28.7.6, 29.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-47136

InDesign Desktop versions 19.5.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha

7.8
CVE-2025-47134

InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul

7.8
CVE-2025-47103

InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul

7.8
CVE-2025-43594

InDesign Desktop versions 19.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in a

7.8
CVE-2025-43592

InDesign Desktop versions 19.5.3 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could

7.8
CVE-2025-43591

InDesign Desktop versions 19.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul

7.3
CVE-2025-7196

A vulnerability was found in code-projects Jonnys Liquor 1.0. It has been rated as critical. Affected by this issue is s

8.8
CVE-2025-7194

A vulnerability was found in D-Link DI-500WF 17.04.10A1T. It has been declared as critical. Affected by this vulnerabili

8.8
CVE-2025-49551

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded Credentials vulnerability t

7.4
CVE-2025-49538

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an XML Injection vulnerability that could lead

7.9
CVE-2025-49537

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Neutralization of Special Elements

7.3
CVE-2025-49536

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Incorrect Authorization vulnerability that c

7.8
CVE-2025-43582

Substance3D - Viewer versions 0.22 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could res

7.3
CVE-2025-7193

A vulnerability was found in itsourcecode Agri-Trading Online Shopping System up to 1.0. It has been classified as criti

7.5
CVE-2025-53355

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. A command injection vulne

7.3
CVE-2025-7191

A vulnerability has been found in code-projects Student Enrollment System 1.0 and classified as critical. This vulnerabi

8.0
CVE-2025-48384 KEV

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-

7.2
CVE-2025-37102

An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Acces

7.8
CVE-2025-30312

Dimension versions 4.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary

8.8
CVE-2025-0928

In Juju versions prior to 3.6.8 and 2.9.52, any authenticated controller user was allowed to upload arbitrary agent bina

8.8
CVE-2025-53513

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on t

8.8
CVE-2025-49753

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

7.0
CVE-2025-49744

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49742

Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.

8.8
CVE-2025-49740

Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a

8.8
CVE-2025-49739

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to eleva

7.8
CVE-2025-49738

Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to

7.0
CVE-2025-49737

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an

8.1
CVE-2025-49735

Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network.

7.8
CVE-2025-49733

Use after free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49732

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49730

Time-of-check time-of-use (toctou) race condition in Microsoft Windows QoS scheduler allows an authorized attacker to el

8.8
CVE-2025-49729

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

7.0
CVE-2025-49727

Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49726

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-49725

Use after free in Windows Notification allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-49724

Use after free in Windows Connected Devices Platform Service allows an unauthorized attacker to execute code over a netw

8.8
CVE-2025-49723

Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.

7.8
CVE-2025-49721

Heap-based buffer overflow in Windows Fast FAT Driver allows an unauthorized attacker to elevate privileges locally.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started