Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 471/1469
7.8
CVE-2025-47382

Memory corruption while loading an invalid firmware in boot loader.

7.8
CVE-2025-47350

Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.

7.8
CVE-2025-47323

Memory corruption while routing GPR packets between user and root when handling large data packet.

7.8
CVE-2025-47322

Memory corruption while handling IOCTL calls to set mode.

7.8
CVE-2025-47321

Memory corruption while copying packets received from unix clients.

7.8
CVE-2025-47320

Memory corruption while processing MFC channel configuration during music playback.

7.8
CVE-2025-27063

Memory corruption during video playback when video session open fails with time out error.

7.2
CVE-2025-68461 KEV

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani

7.2
CVE-2025-68460

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML sty

8.8
CVE-2025-68434

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram

7.7
CVE-2025-68433

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo

7.7
CVE-2025-68432

Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La

7.3
CVE-2025-68429

Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present

8.1
CVE-2025-68147

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram

7.1
CVE-2025-68144

In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments

8.8
CVE-2025-68143

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp

7.6
CVE-2025-66029

Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti

7.3
CVE-2025-14833

A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u

8.8
CVE-2023-53933

Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious

7.5
CVE-2023-53930

ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to do

8.8
CVE-2023-53929

phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into

8.8
CVE-2023-53924

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo

8.8
CVE-2023-53913

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in

8.8
CVE-2023-53908

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol

8.0
CVE-2023-53905

ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in

8.8
CVE-2025-68400

ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo

7.2
CVE-2025-68111

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i

8.8
CVE-2025-67877

ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the

7.3
CVE-2025-14832

A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct

7.8
CVE-2025-67792

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged

7.5
CVE-2025-67790

An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use

7.5
CVE-2025-67493

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e

7.8
CVE-2025-53000

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions

7.8
CVE-2025-46291

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An

8.8
CVE-2025-46281

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macO

8.8
CVE-2025-43529 KEV

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and

7.5
CVE-2025-66646

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT)

8.3
CVE-2025-66397

ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload

7.2
CVE-2025-66396

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th

7.5
CVE-2025-34442

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in

7.5
CVE-2025-34441

AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response

8.1
CVE-2025-34438

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi

8.8
CVE-2025-34437

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The

8.8
CVE-2025-34436

AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due

7.5
CVE-2025-67174

A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a

7.5
CVE-2025-67171

Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d

8.8
CVE-2025-66953

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co

8.8
CVE-2025-66395

ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th

7.8
CVE-2024-46062

Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t

7.8
CVE-2024-46060

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started