Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 617/1469
7.8
CVE-2025-48820

Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized a

7.1
CVE-2025-48819

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an autho

8.8
CVE-2025-48817

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

7.8
CVE-2025-48816

Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-48815

Access of resource using incompatible type ('type confusion') in Windows SSDP Service allows an authorized attacker to e

7.5
CVE-2025-48814

Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker

7.8
CVE-2025-48806

Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

7.8
CVE-2025-48805

Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally.

7.8
CVE-2025-48799

Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker t

7.8
CVE-2025-48000

Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally

8.8
CVE-2025-47998

Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut

7.8
CVE-2025-47996

Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileg

7.8
CVE-2025-47994

Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2025-47993

Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-47991

Use after free in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-47988

Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to exec

7.8
CVE-2025-47987

Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges local

8.8
CVE-2025-47986

Use after free in Universal Print Management Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-47985

Untrusted pointer dereference in Windows Event Tracing allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-47984

Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.

7.8
CVE-2025-47982

Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-47976

Use after free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-47975

Double free in Windows SSDP Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-47973

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

8.0
CVE-2025-47972

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Ed

7.8
CVE-2025-47971

Buffer over-read in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.

8.0
CVE-2025-47178

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager

7.8
CVE-2025-47159

Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to ele

8.1
CVE-2025-33054

Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoo

7.8
CVE-2025-21166

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-21165

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result

7.8
CVE-2025-21164

Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result

7.3
CVE-2025-7185

A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. This vulnerability affe

7.3
CVE-2025-7184

A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. This affects an unkno

7.2
CVE-2025-6771

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re

7.8
CVE-2025-43019

A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to esc

7.0
CVE-2025-7326

Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: Thi

7.3
CVE-2025-7183

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue

7.2
CVE-2025-7037

SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenti

8.4
CVE-2025-6996

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update

8.4
CVE-2025-6995

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update

7.2
CVE-2025-6770

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated atta

7.5
CVE-2025-53372

node-code-sandbox-mcp is a Node.js–based Model Context Protocol server that spins up disposable Docker containers to exe

8.2
CVE-2025-36600

Dell Client Platform BIOS contains an Improper Access Control Applied to Mirrored or Aliased Memory Regions vulnerabilit

7.2
CVE-2024-52965

A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0

7.5
CVE-2025-7345

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64

7.3
CVE-2025-7180

A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue af

7.5
CVE-2025-47422

Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When ru

7.3
CVE-2025-7179

A vulnerability classified as critical was found in code-projects Library System 1.0. This vulnerability affects unknown

7.3
CVE-2025-7178

A vulnerability classified as critical has been found in code-projects Food Distributor Site 1.0. This affects an unknow

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started