Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 466/1469
7.5
CVE-2025-50681

igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft

7.3
CVE-2025-14952

A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /

7.3
CVE-2025-14951

A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk

7.3
CVE-2025-14950

A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio

7.1
CVE-2025-1927

Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al

7.5
CVE-2025-14847 KEV

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe

8.8
CVE-2025-66524

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di

7.2
CVE-2025-14151

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par

7.8
CVE-2025-66499

A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft

7.8
CVE-2025-66495

A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1

7.8
CVE-2025-66494

A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on

7.8
CVE-2025-66493

A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,

7.2
CVE-2025-13999

The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S

7.2
CVE-2025-13307

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic.

7.3
CVE-2025-14940

A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio

8.3
CVE-2025-67843

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15

8.8
CVE-2025-52692

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially craft

8.8
CVE-2025-13941

A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installat

8.2
CVE-2025-11774

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software

8.3
CVE-2025-64675

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauth

7.2
CVE-2025-68385

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us

7.7
CVE-2025-68279

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the

8.2
CVE-2025-64677

Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience all

7.2
CVE-2025-64676

'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.

7.8
CVE-2025-34451

rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflo

7.8
CVE-2025-34450

merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vu

7.5
CVE-2025-63951

An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project thro

7.5
CVE-2025-63950

An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through co

7.5
CVE-2025-62004

BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local,

7.5
CVE-2025-62003

BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connect

8.8
CVE-2025-62001

BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance mo

7.1
CVE-2025-62000

BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection m

7.5
CVE-2025-53710

Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace

8.1
CVE-2025-14850

Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.

8.8
CVE-2025-14849

Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar

7.5
CVE-2025-65566

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.

8.8
CVE-2023-53942

File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious

7.8
CVE-2023-53940

Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system comma

7.8
CVE-2023-53937

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32

7.5
CVE-2023-53934

A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requ

7.5
CVE-2022-50686

An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via

7.5
CVE-2021-47712

A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through exi

8.8
CVE-2021-47711

A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via onli

7.2
CVE-2020-36890

An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user pr

8.8
CVE-2019-25229

An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions t

7.1
CVE-2025-67745

MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1

7.5
CVE-2025-65568

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.

7.5
CVE-2025-65567

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.

7.5
CVE-2025-65565

A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.

7.5
CVE-2025-65564

A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. Whe

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started