Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 665/1469
7.5
CVE-2025-24308

Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privi

7.8
CVE-2025-22843

Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow

7.5
CVE-2025-21094

Improper input validation in the UEFI firmware DXE module for the Intel(R) Server D50DNP and M50FCP boards may allow a p

7.9
CVE-2025-20618

Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow

7.3
CVE-2025-20104

Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an

8.4
CVE-2025-20101

Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information

7.5
CVE-2025-20100

Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may a

7.5
CVE-2025-20083

Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enab

7.5
CVE-2025-20082

Time-of-check time-of-use race condition in the UEFI firmware SmiVariable driver for the Intel(R) Server D50DNP and M50F

7.3
CVE-2025-20052

Improper access control for some Intel(R) Graphics software may allow an authenticated user to potentially enable denial

8.0
CVE-2025-20046

Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti

7.9
CVE-2025-20032

Improper input validation for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow a

8.4
CVE-2025-20018

Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable e

7.7
CVE-2025-20008

Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a pr

7.4
CVE-2025-20006

Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenti

7.2
CVE-2025-20004

Insufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores

8.2
CVE-2025-20003

Improper link resolution before file access ('Link Following') for some Intel(R) Graphics Driver software installers may

7.3
CVE-2024-45333

Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.4314 ma

7.3
CVE-2024-36292

Improper buffer restrictions for some Intel(R) Data Center GPU Flex Series for Windows driver before version 31.0.101.43

7.6
CVE-2025-3744

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vul

7.8
CVE-2025-43557

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could

7.8
CVE-2025-43556

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could

7.8
CVE-2025-43555

Animate versions 24.0.8, 23.0.11 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha

7.8
CVE-2025-43547

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could re

7.8
CVE-2025-43546

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that

7.8
CVE-2025-43545

Bridge versions 15.0.3, 14.1.6 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could r

7.8
CVE-2025-30330

Illustrator versions 29.3, 28.7.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu

7.8
CVE-2025-30328

Animate versions 24.0.8, 23.0.11 and earlier are affected by an out-of-bounds write vulnerability that could result in a

7.8
CVE-2025-30326

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Access of Uninitialized Pointer vulnerability th

7.8
CVE-2025-30325

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Overflow or Wraparound vulnerability tha

7.8
CVE-2025-30324

Photoshop Desktop versions 26.5, 25.12.2 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi

7.8
CVE-2025-30322

Substance3D - Painter versions 11.0 and earlier are affected by an out-of-bounds write vulnerability that could result i

7.8
CVE-2025-27197

Lightroom Desktop versions 8.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arb

7.3
CVE-2023-31359

Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote

7.3
CVE-2023-31358

A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, pote

7.8
CVE-2025-32709 KEV

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privi

7.8
CVE-2025-32707

Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally.

7.8
CVE-2025-32706 KEV

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges l

7.8
CVE-2025-32705

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-32704

Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-32702

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthori

7.8
CVE-2025-32701 KEV

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-30400 KEV

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

7.5
CVE-2025-30397 KEV

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attac

7.8
CVE-2025-30393

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30388

Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

8.4
CVE-2025-30386

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

7.8
CVE-2025-30385

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

7.4
CVE-2025-30384

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally

7.8
CVE-2025-30383

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started