Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 548/1469
7.5
CVE-2025-59420

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific

7.5
CVE-2025-57440

The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated

8.8
CVE-2025-57439

Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo

7.3
CVE-2025-55888

Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can

8.8
CVE-2025-43953

In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr

7.3
CVE-2025-10809

A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is a

7.3
CVE-2025-10808

A weakness has been identified in Campcodes Farm Management System 1.0. Impacted is an unknown function of the file /upl

7.1
CVE-2025-59335

CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration

8.8
CVE-2025-57434

Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The

8.8
CVE-2025-57431

The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici

8.8
CVE-2025-57605

Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users

7.5
CVE-2025-57430

Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When access

7.5
CVE-2025-36202

IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute co

7.5
CVE-2025-35041

Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A r

8.8
CVE-2025-10803

A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of

7.3
CVE-2025-10802

A flaw has been found in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /administr

7.8
CVE-2025-51006

Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function i

7.3
CVE-2025-10801

A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unkno

7.3
CVE-2025-10800

A weakness has been identified in itsourcecode Online Discussion Forum 1.0. The impacted element is an unknown function

8.1
CVE-2025-10854

The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is inte

7.3
CVE-2025-10799

A security flaw has been discovered in code-projects Hostel Management System 1.0. The affected element is an unknown fu

7.3
CVE-2025-10798

A vulnerability was identified in code-projects Hostel Management System 1.0. Impacted is an unknown function of the fil

7.3
CVE-2025-10797

A vulnerability was determined in code-projects Hostel Management System 1.0. This issue affects some unknown processing

7.3
CVE-2025-10796

A vulnerability was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the

7.3
CVE-2025-10795

A vulnerability has been found in code-projects Online Bidding System 1.0. This affects an unknown part of the file /adm

7.3
CVE-2025-10793

A vulnerability was detected in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown funct

8.8
CVE-2025-10792

A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /gofor

7.3
CVE-2025-10791

A weakness has been identified in code-projects Online Bidding System 1.0. This impacts an unknown function of the file

7.7
CVE-2025-5962

A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc

7.3
CVE-2025-10789

A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. The impacted element is an unknown

7.3
CVE-2025-10788

A vulnerability was determined in SourceCodester Online Hotel Reservation System 1.0. The affected element is an unknown

7.3
CVE-2025-10786

A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This vulnerability affects unknown code of th

7.3
CVE-2025-10785

A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown part of the fi

7.3
CVE-2025-10784

A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. Affected by this issue is

7.3
CVE-2025-10783

A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected by this vulnerability is an

7.3
CVE-2025-10782

A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Affected is an unknown function

7.3
CVE-2025-10781

A vulnerability was identified in Campcodes Online Learning Management System 1.0. This impacts an unknown function of t

8.8
CVE-2025-10779

A vulnerability was found in D-Link DCS-935L up to 1.13.01. The impacted element is the function sub_402280 of the file

8.8
CVE-2025-10773

A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath o

7.1
CVE-2025-53692

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Si

8.8
CVE-2025-10757

A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file

8.8
CVE-2025-10756

A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /g

8.0
CVE-2025-9079

Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to

8.8
CVE-2025-54815

Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via craft

8.0
CVE-2025-54761

An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.

8.8
CVE-2025-52159

Hardcoded credentials in default configuration of PPress 0.0.9.

8.8
CVE-2025-34202

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and

7.8
CVE-2025-34201

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker co

7.8
CVE-2025-34200

Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the app

8.1
CVE-2025-34199

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior t

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started