Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 591/1469
7.1
CVE-2025-55008

The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKi

7.2
CVE-2025-54996

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi

8.8
CVE-2025-54417

Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a v

7.3
CVE-2025-8744

A vulnerability classified as critical was found in CesiumLab Web up to 4.0. This vulnerability affects unknown code of

7.5
CVE-2025-46709

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern

8.8
CVE-2025-4796

The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i

8.8
CVE-2025-52914

A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a

7.3
CVE-2025-8393

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts se

8.8
CVE-2025-53520

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or insta

7.1
CVE-2025-50466

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l

7.1
CVE-2025-50465

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l

8.1
CVE-2025-46414

The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, whic

7.5
CVE-2025-8355

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker

7.1
CVE-2025-36119

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certifi

8.8
CVE-2020-9322

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CS

8.8
CVE-2025-8088 KEV

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by

8.8
CVE-2025-8748

MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP reques

8.4
CVE-2025-54886

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below

8.2
CVE-2025-53787

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability

7.0
CVE-2025-26513

The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ

8.1
CVE-2025-47219

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil

7.4
CVE-2025-55077

Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s

7.8
CVE-2025-50675

GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati

8.8
CVE-2025-51629

A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker

8.8
CVE-2023-41532

Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter i

8.8
CVE-2023-41531

Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the user

8.8
CVE-2023-41524

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username paramet

8.8
CVE-2023-41523

Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress par

8.8
CVE-2023-41522

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStuden

8.8
CVE-2023-41521

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessio

8.8
CVE-2023-41520

Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassA

7.4
CVE-2025-55138

LinkJoin through 882f196 mishandles token ownership in password reset.

7.4
CVE-2025-55137

LinkJoin through 882f196 mishandles lacks type checking in password reset.

8.8
CVE-2025-24000

Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti

7.0
CVE-2025-47907

Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method

7.5
CVE-2025-35970

On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t

8.8
CVE-2025-8578

Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor

8.8
CVE-2025-8576

Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he

7.1
CVE-2025-54882

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.

7.0
CVE-2025-3770

EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes

8.8
CVE-2025-54788

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an

8.8
CVE-2025-54785

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.

7.8
CVE-2025-6634

A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili

7.8
CVE-2025-6633

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A

8.2
CVE-2025-51056

An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t

8.6
CVE-2025-51055

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202

7.5
CVE-2025-47908

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A

7.6
CVE-2025-51624

Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.

7.5
CVE-2025-46659

An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT

7.0
CVE-2025-45766

poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started