Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 561/1469
7.8
CVE-2025-54098

Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-54093

Time-of-check time-of-use (toctou) race condition in Windows TCP/IP allows an authorized attacker to elevate privileges

7.8
CVE-2025-54092

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an

7.8
CVE-2025-54091

Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

7.0
CVE-2025-53807

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Compon

7.5
CVE-2025-53805

Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a netwo

7.0
CVE-2025-53802

Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-53801

Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.

7.8
CVE-2025-53800

No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

8.8
CVE-2025-53303

Deserialization of Untrusted Data vulnerability in ThemeMove ThemeMove Core thememove-core allows Object Injection.This

7.0
CVE-2025-49734

Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker

7.8
CVE-2025-49692

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges local

7.2
CVE-2025-49430

Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request For

8.8
CVE-2025-48101

Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection.

7.5
CVE-2025-47695

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-47694

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in solwin Blog Design

7.5
CVE-2025-47571

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-47570

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in villatheme WooComm

7.5
CVE-2025-32689

Improper Validation of Specified Quantity in Input vulnerability in Convers Lab WP SmartPay smartpay.This issue affects

8.8
CVE-2025-9872

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe

8.8
CVE-2025-9712

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthe

7.6
CVE-2025-55148

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z

8.8
CVE-2025-55147

CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before

8.9
CVE-2025-55145

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z

8.8
CVE-2025-55142

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z

8.8
CVE-2025-55141

Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti Z

7.2
CVE-2025-52915

K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCT

7.5
CVE-2025-52322

An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session

8.2
CVE-2025-33045

APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure

8.8
CVE-2025-9364

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redi

7.5
CVE-2025-9166

A denial-of-service security issue exists in the affected product and version. The security issue stems from the control

8.8
CVE-2025-9161

A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the

8.8
CVE-2025-9065

A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of

7.5
CVE-2025-7970

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within th

8.8
CVE-2025-48208

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat .

8.8
CVE-2025-24404

XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs t

8.8
CVE-2025-59017

Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47,

7.8
CVE-2025-41701

An unauthenticated attacker can trick a local user into executing arbitrary commands by opening a deliberately manipulat

7.5
CVE-2025-40798

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC

7.5
CVE-2025-40797

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC

7.5
CVE-2025-40796

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC

8.0
CVE-2025-9539

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

7.3
CVE-2025-10123

A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_41502

8.8
CVE-2025-42933

When a user logs in via SAP Business One native client, the SLD backend service fails to enforce proper encryption of ce

8.1
CVE-2025-42929

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi

8.1
CVE-2025-42916

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbi

8.8
CVE-2025-10120

A vulnerability was detected in Tenda AC20 up to 16.03.08.12. The impacted element is the function strcpy of the file /g

7.3
CVE-2025-10118

A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The

7.3
CVE-2025-10116

A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admi

7.3
CVE-2025-10115

A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started