Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 492/1469
7.5
CVE-2025-61618

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-61617

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-61610

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-61609

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

7.5
CVE-2025-61608

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-61607

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-3012

In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of serv

7.3
CVE-2025-13814

A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.

7.5
CVE-2025-11133

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-11132

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.5
CVE-2025-11131

In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv

7.3
CVE-2025-13808

A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerabili

7.3
CVE-2025-13806

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of

7.3
CVE-2025-13803

A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /media

7.8
CVE-2025-64772

The installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurel

7.3
CVE-2025-13792

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function e

7.3
CVE-2025-13788

A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /t

7.3
CVE-2025-13786

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fe

7.3
CVE-2025-13782

A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is

7.1
CVE-2025-66423

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.1

8.8
CVE-2025-66289

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not i

8.8
CVE-2025-66225

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo

8.8
CVE-2025-66224

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains a

7.5
CVE-2025-66217

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQ

7.2
CVE-2025-53899

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is

7.1
CVE-2025-53896

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus

8.1
CVE-2025-66201

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-sid

7.5
CVE-2025-51735

CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.

8.0
CVE-2025-12638

Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin

7.5
CVE-2025-13768

WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in

8.2
CVE-2025-66384

app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela

7.3
CVE-2025-58308

Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi

8.4
CVE-2025-58302

Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec

7.3
CVE-2025-58316

DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may

8.0
CVE-2025-58310

Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may

8.4
CVE-2025-58303

UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af

8.8
CVE-2025-66360

An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo

8.5
CVE-2025-66359

An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl

8.8
CVE-2025-13757

SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025

7.2
CVE-2025-13692

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo

7.3
CVE-2025-59890

Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths

8.8
CVE-2025-13536

The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida

7.5
CVE-2025-7820

The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including

8.8
CVE-2025-13680

The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This

7.5
CVE-2025-12758

Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe

7.5
CVE-2025-66314

Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper

7.5
CVE-2025-66031

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R

7.5
CVE-2025-64344

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric

7.5
CVE-2025-64335

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric

7.5
CVE-2025-64334

Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started