Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 542/1469
7.5
CVE-2025-54591

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below expose information about feeds and tags of d

7.5
CVE-2025-45376

Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Pr

7.8
CVE-2025-34235

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2

7.5
CVE-2025-34234

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2

8.6
CVE-2025-34231

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2

8.6
CVE-2025-34228

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2

8.6
CVE-2025-34225

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 2

7.2
CVE-2025-34209

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application prior to 20.0.2014 (VA and

8.1
CVE-2025-35030

Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthen

7.3
CVE-2025-57424

A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile fi

7.5
CVE-2025-41252

Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit th

8.1
CVE-2025-41251

VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit thi

8.1
CVE-2025-57483

A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary

8.5
CVE-2025-41250

VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on

7.5
CVE-2025-7104

A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attac

7.5
CVE-2025-56234

AT_NA2000 from Nanda Automation Technology vendor has a denial-of-service vulnerability. For the processing of TCP RST p

7.5
CVE-2025-56233

Openindiana, kernel SunOS 5.11 has a denial of service vulnerability. For the processing of TCP packets with RST or SYN

7.5
CVE-2025-51495

An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially cr

7.8
CVE-2025-41244 KEV

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with

7.5
CVE-2024-57412

An issue in SunOS Omnios v5.11 allows attackers to cause a Denial of Service (DoS) via repeatedly sending crafted TCP pa

7.6
CVE-2025-41246

VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls

8.2
CVE-2025-57516

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to e

8.2
CVE-2025-56449

A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out d

8.8
CVE-2025-6724

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain acc

7.3
CVE-2025-11140

A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm

7.3
CVE-2025-11135

A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486. The

8.4
CVE-2025-11130

A weakness has been identified in iHongRen pptp-vpn 1.0/1.0.1 on macOS. This issue affects the function shouldAcceptNewC

8.8
CVE-2025-11123

A flaw has been found in Tenda AC18 15.03.05.19. This impacts an unknown function of the file /goform/saveAutoQos. This

8.8
CVE-2025-11122

A vulnerability was detected in Tenda AC18 15.03.05.19. This affects an unknown function of the file /goform/WizardHandl

8.8
CVE-2025-11120

A weakness has been identified in Tenda AC8 16.03.34.06. The affected element is the function formSetServerConfig of the

7.3
CVE-2025-11118

A vulnerability was identified in CodeAstro Student Grading System 1.0. This issue affects some unknown processing of th

8.8
CVE-2025-11117

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formWrlExtraGet of the fil

7.3
CVE-2025-11116

A vulnerability was found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /add.h

7.3
CVE-2025-11115

A vulnerability has been found in code-projects Simple Scheduling System 1.0. Affected by this issue is some unknown fun

7.3
CVE-2025-11111

A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown functi

7.3
CVE-2025-11110

A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unkno

7.3
CVE-2025-11109

A vulnerability was identified in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown

7.3
CVE-2025-11108

A vulnerability was determined in code-projects Simple Scheduling System 1.0. Impacted is an unknown function of the fil

7.3
CVE-2025-11107

A vulnerability was found in code-projects Simple Scheduling System 1.0. This issue affects some unknown processing of t

7.3
CVE-2025-11106

A vulnerability has been found in code-projects Simple Scheduling System 1.0. This vulnerability affects unknown code of

7.3
CVE-2025-11105

A flaw has been found in code-projects Simple Scheduling System 1.0. This affects an unknown part of the file /schedulin

7.3
CVE-2025-11102

A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected is an unknown function of th

7.3
CVE-2025-11101

A security flaw has been discovered in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function of the

7.3
CVE-2025-11094

A security vulnerability has been detected in code-projects E-Commerce Website 1.0. This affects an unknown part of the

8.8
CVE-2025-11091

A security flaw has been discovered in Tenda AC21 up to 16.03.08.16. Affected by this vulnerability is the function ssca

7.3
CVE-2025-11089

A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This impa

7.3
CVE-2025-11077

A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of th

7.3
CVE-2025-11076

A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the fi

7.3
CVE-2025-11075

A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of t

7.3
CVE-2025-11074

A flaw has been found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of the

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started