Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 530/1469
8.1
CVE-2025-11720

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full

8.8
CVE-2025-11715

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these b

8.8
CVE-2025-11714

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird

8.1
CVE-2025-11713

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code

7.8
CVE-2025-40812

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi

7.8
CVE-2025-40811

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi

7.8
CVE-2025-40810

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi

7.8
CVE-2025-40809

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi

7.4
CVE-2025-40772

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnera

8.8
CVE-2025-40755

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL

7.8
CVE-2025-20723

In gnss driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escal

7.8
CVE-2025-20721

In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation

8.8
CVE-2025-20720

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

8.8
CVE-2025-20719

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

7.8
CVE-2025-20718

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20717

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20716

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20715

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20714

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20713

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

8.8
CVE-2025-20712

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

8.8
CVE-2025-20711

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

8.8
CVE-2025-20710

In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proxim

8.8
CVE-2025-20709

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

8.8
CVE-2025-10228

Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affect

7.4
CVE-2011-20002

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SI

7.5
CVE-2011-20001

A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SI

7.5
CVE-2025-41718

A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote a

8.8
CVE-2025-41699

An low privileged remote attacker with an account for the Web-based management can change the system configuration to pe

7.5
CVE-2025-41703

An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command

8.6
CVE-2025-59889

Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of a

7.8
CVE-2025-62363

yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the applicati

8.8
CVE-2025-62360

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Inj

8.8
CVE-2025-62179

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In

8.8
CVE-2025-62177

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In

8.8
CVE-2025-9713

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re

8.6
CVE-2025-61688

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensit

7.8
CVE-2025-11622

Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to esc

7.5
CVE-2025-62170

rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality

7.8
CVE-2025-7707

The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which

8.0
CVE-2025-11695

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects M

7.8
CVE-2025-39965

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.

7.8
CVE-2025-39964

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a

7.5
CVE-2025-9902

Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trad

7.2
CVE-2025-11675

Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote atta

7.2
CVE-2025-11673

SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploi

8.7
CVE-2025-10558

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows a

8.7
CVE-2025-10557

A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator

8.7
CVE-2025-10556

A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager fro

8.7
CVE-2025-10552

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started