Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 594/1469
8.8
CVE-2025-20701

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou

8.8
CVE-2025-20700

In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc

7.3
CVE-2025-8503

A vulnerability, which was classified as critical, has been found in code-projects Online Medicine Guide 1.0. Affected b

7.3
CVE-2025-8502

A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerabil

7.3
CVE-2025-8499

A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerabili

7.3
CVE-2025-8498

A security vulnerability has been detected in code-projects Online Medicine Guide 1.0. This vulnerability affects unknow

7.3
CVE-2025-8497

A weakness has been identified in code-projects Online Medicine Guide 1.0. This affects an unknown part of the file /cus

7.3
CVE-2025-8496

A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-8495

A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. A

8.9
CVE-2025-54351

In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).

7.3
CVE-2025-8494

A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1

8.1
CVE-2025-54955

OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race c

7.3
CVE-2025-8493

A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerab

7.8
CVE-2025-23284

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack bu

7.8
CVE-2025-23283

NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious

7.0
CVE-2025-23281

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can

7.0
CVE-2025-23279

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to esc

7.1
CVE-2025-23278

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index val

7.3
CVE-2025-23277

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could

7.8
CVE-2025-23276

NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful

7.3
CVE-2025-8471

A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This iss

7.3
CVE-2025-8470

A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerabili

7.3
CVE-2025-8469

A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affect

7.3
CVE-2025-8468

A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is s

7.3
CVE-2025-8467

A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnera

7.3
CVE-2025-8466

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an un

8.8
CVE-2025-6754

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t

8.8
CVE-2025-6076

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor

7.5
CVE-2025-54796

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows

8.8
CVE-2025-54782

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo

7.2
CVE-2025-54136

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per

8.1
CVE-2025-54424

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server

7.2
CVE-2013-10061

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver

7.2
CVE-2013-10060

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve

7.2
CVE-2013-10059

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa

8.8
CVE-2013-10050

An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re

8.8
CVE-2013-10044

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to

8.0
CVE-2025-8480

Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute

7.4
CVE-2025-8477

Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows

8.0
CVE-2025-8476

Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers

7.4
CVE-2025-8475

Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-

7.4
CVE-2025-8472

Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows

7.2
CVE-2025-5999

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or

7.3
CVE-2025-54595

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he

7.2
CVE-2025-54593

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can

7.8
CVE-2025-54564

uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow

7.5
CVE-2025-53012

MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren

7.5
CVE-2025-53011

MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren

7.5
CVE-2025-53010

MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren

7.5
CVE-2025-53009

MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started