Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 567/1469
8.4
CVE-2025-36899

There is a possible escalation of privilege due to test/debugging code left in a production build. This could lead to ph

7.8
CVE-2025-36898

There is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of pri

7.5
CVE-2025-36895

Information disclosure

7.5
CVE-2025-36894

In TBD of TBD, there is a possible DoS due to a missing null check. This could lead to remote denial of service with no

7.5
CVE-2025-36892

Denial of service

8.8
CVE-2025-36891

Elevation of privilege

7.8
CVE-2025-36887

In wl_cfgscan_update_v3_schedscan_results() of wl_cfgscan.c, there is a possible out of bounds write due to an incorrec

8.6
CVE-2025-2417

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft e-Mutabakat allows Authentication By

8.6
CVE-2025-2411

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft TaskPano allows Authentication Bypas

7.8
CVE-2024-56190

In wl_update_hidden_ap_ie() of wl_cfgscan.c, there is a possible out of bounds write due to improper input validation. T

7.3
CVE-2025-9928

A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown fu

7.3
CVE-2025-9927

A vulnerability was identified in projectworlds Travel Management System 1.0. The affected element is an unknown functio

7.5
CVE-2025-58056

Netty is an asynchronous event-driven network application framework for development of maintainable high performance pro

7.1
CVE-2025-57833

An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subjec

7.5
CVE-2025-55748

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2

7.3
CVE-2025-9926

A vulnerability was determined in projectworlds Travel Management System 1.0. Impacted is an unknown function of the fil

7.3
CVE-2025-9925

A vulnerability was found in projectworlds Travel Management System 1.0. This issue affects some unknown processing of t

7.8
CVE-2025-9365

Fuji Electric FRENIC-Loader 4 is vulnerable to a deserialization of untrusted data when importing a file through a speci

7.3
CVE-2025-9924

A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of

8.4
CVE-2025-36193

IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could all

8.4
CVE-2025-56803

Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An atta

7.5
CVE-2025-52494

Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling o

7.6
CVE-2025-45805

In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript cod

7.6
CVE-2025-9959

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sand

8.8
CVE-2025-9866

Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass c

7.3
CVE-2025-9919

A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of

7.5
CVE-2025-55852

Tenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or s

7.5
CVE-2025-0280

A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.

7.2
CVE-2025-58644

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes

7.2
CVE-2025-58643

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Daylight Edition ltl-freight-q

7.2
CVE-2025-58642

Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes – Day & Ross Edition ltl-freight

7.5
CVE-2025-58637

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2025-58608

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.6
CVE-2025-58604

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min

8.8
CVE-2025-57151

phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the

7.2
CVE-2025-57150

phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php v

7.5
CVE-2025-57147

A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack

8.1
CVE-2025-57146

phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobi

8.6
CVE-2025-2416

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypa

8.8
CVE-2025-26210

DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepsee

7.3
CVE-2024-13068

Origin Validation Error vulnerability in Akinsoft LimonDesk allows Forceful Browsing. This issue affects LimonDesk: fro

7.5
CVE-2025-53694

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), S

8.8
CVE-2025-53691

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) a

7.8
CVE-2025-38678

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on up

8.6
CVE-2025-2415

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft MyRezzta allows Authentication Bypas

8.8
CVE-2024-43115

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script s

7.5
CVE-2014-125127

The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager

7.8
CVE-2025-9817

SSH dissector crash in Wireshark 4.4.0 to 4.4.8 allows denial of service

8.5
CVE-2023-21480

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch pri

7.9
CVE-2023-21477

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows lo

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started