Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 783/1469
7.5
CVE-2025-21290

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.5
CVE-2025-21289

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.8
CVE-2025-21287

Windows Installer Elevation of Privilege Vulnerability

8.8
CVE-2025-21286

Windows Telephony Service Remote Code Execution Vulnerability

7.5
CVE-2025-21285

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

8.8
CVE-2025-21282

Windows Telephony Service Remote Code Execution Vulnerability

7.8
CVE-2025-21281

Microsoft COM for Windows Elevation of Privilege Vulnerability

7.5
CVE-2025-21277

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.5
CVE-2025-21276

Windows MapUrlToZone Denial of Service Vulnerability

7.8
CVE-2025-21275

Windows App Package Installer Elevation of Privilege Vulnerability

8.8
CVE-2025-21273

Windows Telephony Service Remote Code Execution Vulnerability

7.8
CVE-2025-21271

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.5
CVE-2025-21270

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

8.8
CVE-2025-21266

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21252

Windows Telephony Service Remote Code Execution Vulnerability

7.5
CVE-2025-21251

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

8.8
CVE-2025-21250

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21248

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21246

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21245

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21244

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21243

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21241

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21240

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21239

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21238

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21237

Windows Telephony Service Remote Code Execution Vulnerability

8.8
CVE-2025-21236

Windows Telephony Service Remote Code Execution Vulnerability

7.8
CVE-2025-21235

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

7.8
CVE-2025-21234

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

8.8
CVE-2025-21233

Windows Telephony Service Remote Code Execution Vulnerability

7.5
CVE-2025-21231

IP Helper Denial of Service Vulnerability

7.5
CVE-2025-21230

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

8.1
CVE-2025-21224

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

8.8
CVE-2025-21223

Windows Telephony Service Remote Code Execution Vulnerability

7.5
CVE-2025-21220

Microsoft Message Queuing Information Disclosure Vulnerability

7.5
CVE-2025-21218

Windows Kerberos Denial of Service Vulnerability

7.5
CVE-2025-21207

Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability

7.8
CVE-2025-21187

Microsoft Power Automate Remote Code Execution Vulnerability

7.8
CVE-2025-21186

Microsoft Access Remote Code Execution Vulnerability

8.8
CVE-2025-21178

Visual Studio Remote Code Execution Vulnerability

8.8
CVE-2025-21176

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

7.3
CVE-2025-21173

.NET Elevation of Privilege Vulnerability

7.5
CVE-2025-21172

.NET and Visual Studio Remote Code Execution Vulnerability

7.5
CVE-2025-21171

.NET Remote Code Execution Vulnerability

7.3
CVE-2025-0465

A vulnerability was found in AquilaCMS 1.412.13. It has been rated as critical. Affected by this issue is some unknown f

7.8
CVE-2024-13172

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Sec

7.8
CVE-2024-13171

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Se

7.5
CVE-2024-13170

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd

7.8
CVE-2024-13169

An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upda

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started