Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 569/1469
7.8
CVE-2025-57777

There is an out of bounds write vulnerability due to improper bounds checking in displ2.dll when parsing a DSB file with

7.8
CVE-2025-57776

There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsi

7.8
CVE-2025-57775

There is a heap-based Buffer Overflow vulnerability due to improper bounds checking when parsing a DSB file with Digilen

7.8
CVE-2025-57774

There is an out of bounds write vulnerability due to improper bounds checking resulting in invalid data when parsing a D

7.5
CVE-2025-57616

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleav

7.5
CVE-2025-57615

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new

7.5
CVE-2025-57614

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in t

7.5
CVE-2025-57613

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input

7.5
CVE-2025-57612

An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name()

7.5
CVE-2025-54599

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover,

7.5
CVE-2025-9784

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering ab

8.6
CVE-2025-2413

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypa

7.2
CVE-2025-52550

E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge ma

7.5
CVE-2025-52547

E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacke

7.5
CVE-2025-52545

E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which retur

7.5
CVE-2025-52544

E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta

7.5
CVE-2025-52543

E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for

8.6
CVE-2025-2414

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypa

8.2
CVE-2024-58259

A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert

7.7
CVE-2024-52284

Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou

7.4
CVE-2025-41690

A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)

7.8
CVE-2025-9815

A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o

7.3
CVE-2025-9814

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function

8.8
CVE-2025-9813

A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /gofo

8.8
CVE-2025-9812

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file

7.3
CVE-2025-9811

A vulnerability was found in Campcodes Farm Management System 1.0. This affects an unknown part of the file /reviewInput

7.8
CVE-2025-58178

SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In version

8.1
CVE-2025-57808

ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP

7.3
CVE-2025-9794

A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function

7.3
CVE-2025-9793

A vulnerability was detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the fil

7.3
CVE-2025-9792

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. This issue affects some unkn

8.8
CVE-2025-9791

A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fr

7.3
CVE-2025-9790

A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the

7.3
CVE-2025-9789

A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is some unk

7.3
CVE-2025-9788

A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerabil

7.2
CVE-2025-3586

In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10,

7.3
CVE-2025-9786

A vulnerability was found in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the fil

8.8
CVE-2025-9783

A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the

8.8
CVE-2025-9782

A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of

8.8
CVE-2025-9781

A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file

8.8
CVE-2025-9780

A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the f

8.8
CVE-2025-9779

A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_

8.6
CVE-2025-2412

Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass

8.6
CVE-2025-0610

Cross-Site Request Forgery (CSRF) vulnerability in Akınsoft QR Menü allows Cross Site Request Forgery. This issue affec

7.3
CVE-2024-12925

Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting.

7.3
CVE-2025-9775

A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.

7.3
CVE-2025-9772

A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Perfor

7.3
CVE-2025-9771

A security vulnerability has been detected in SourceCodester Eye Clinic Management System 1.0. Affected by this issue is

7.3
CVE-2025-9770

A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown

7.8
CVE-2022-38695

In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additio

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started