Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 532/1469
7.8
CVE-2025-61862

An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening sp

7.8
CVE-2025-61861

An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially

7.8
CVE-2025-61860

An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening sp

7.8
CVE-2025-61859

An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Open

7.8
CVE-2025-61858

An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening speci

7.8
CVE-2025-61857

An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlie

7.8
CVE-2025-61856

A stack-based buffer overflow vulnerability exists in VS6ComFile!CV7BaseMap::WriteV7DataToRom of V-SFT v6.2.7.0 and earl

7.3
CVE-2025-11189

The Kiwire Captive Portal contains a reflected cross-site scripting (XSS) vulnerability within the login-url parameter,

7.3
CVE-2025-11188

The Kiwire Captive Portal contains a blind SQL injection in the nas-id parameter, allowing for SQL commands to be issued

8.2
CVE-2025-52650

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

7.3
CVE-2025-30001

Incorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from

8.7
CVE-2025-25018

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

8.2
CVE-2025-25017

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

8.8
CVE-2025-21064

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

7.8
CVE-2025-21062

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to rep

7.1
CVE-2025-21061

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access se

7.3
CVE-2025-21058

Improper access control in Routines prior to version 4.8.7.1 in Android 15 and 4.9.6.0 in Android 16 allows local attack

7.1
CVE-2025-21050

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across mult

8.1
CVE-2025-61773

pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte

7.5
CVE-2025-61602

BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 a

7.5
CVE-2025-61601

BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 a

7.3
CVE-2025-60375

The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient

8.7
CVE-2025-59271

Redis Enterprise Elevation of Privilege Vulnerability

8.8
CVE-2025-59247

Azure PlayFab Elevation of Privilege Vulnerability

8.8
CVE-2025-35055

Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar

7.3
CVE-2025-11558

A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/us

7.3
CVE-2025-11557

A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown process

7.3
CVE-2025-11556

A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /us

7.3
CVE-2025-11555

A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the fil

8.5
CVE-2025-59146

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticate

7.1
CVE-2025-55200

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a St

7.2
CVE-2025-4615

An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar

7.5
CVE-2025-11573

An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of servic

7.5
CVE-2025-60004

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne

8.8
CVE-2025-11549

A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the

7.5
CVE-2025-11371 KEV

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local Fil

7.5
CVE-2025-61577

D-Link DIR-816A2_FWv1.10CNB05 was discovered to contain a stack overflow via the statuscheckpppoeuser parameter in the d

7.5
CVE-2025-59975

An Uncontrolled Resource Consumption vulnerability in the HTTP daemon (httpd) of Juniper Networks Junos Space allows an

8.4
CVE-2025-59974

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Sec

8.6
CVE-2025-59968

A Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated ne

7.5
CVE-2025-59964

A Use of Uninitialized Resource vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX4

7.4
CVE-2025-11198

A Missing Authentication for Critical Function vulnerability in Juniper Networks Security Director Policy Enforcer allow

7.3
CVE-2025-45095

Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCISer

7.8
CVE-2025-32919

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Esca

8.8
CVE-2025-62228

Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted databas

8.8
CVE-2025-11561

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems.

7.8
CVE-2025-39963

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix incorrect io_kiocb reference in io_li

7.5
CVE-2025-39962

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix untrusted unsigned subtract Fix the fol

8.8
CVE-2025-39961

In the Linux kernel, the following vulnerability has been resolved: iommu/amd/pgtbl: Fix possible race while increase p

7.3
CVE-2025-39960

In the Linux kernel, the following vulnerability has been resolved: gpiolib: acpi: initialize acpi_gpio_info struct Si

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started