Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 596/1469
8.8
CVE-2025-53558

ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o

8.8
CVE-2025-7847

The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the re

7.3
CVE-2025-8348

A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability

7.3
CVE-2025-8339

A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical.

7.3
CVE-2025-8338

A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issu

7.2
CVE-2025-49083

CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to v

7.3
CVE-2025-8336

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili

7.3
CVE-2025-8334

A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected

7.1
CVE-2025-54586

GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, att

7.3
CVE-2025-8333

A vulnerability was found in code-projects Online Farm System 1.0. It has been declared as critical. Affected by this vu

7.3
CVE-2025-8332

A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an un

7.3
CVE-2025-8331

A vulnerability was found in code-projects Online Farm System 1.0 and classified as critical. This issue affects some un

7.3
CVE-2025-8330

A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability af

7.5
CVE-2025-54581

vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-cont

8.6
CVE-2025-53022

TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validat

8.2
CVE-2025-52187

GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_for

8.1
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an

7.3
CVE-2025-8329

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an un

7.8
CVE-2025-50777

The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Acc

7.3
CVE-2025-8328

A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by

7.3
CVE-2025-8327

A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerabili

8.8
CVE-2025-30105

Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p

8.8
CVE-2025-26332

TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log

8.1
CVE-2025-45620

An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request

7.3
CVE-2025-36611

Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Befo

7.3
CVE-2024-45955

Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.

7.1
CVE-2025-8312

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its

7.7
CVE-2025-53944

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6

7.3
CVE-2025-8326

A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown

7.8
CVE-2025-38498

In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/no

8.8
CVE-2025-8323

The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload

8.8
CVE-2025-8322

The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to

8.8
CVE-2025-8292

Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit

8.8
CVE-2025-8320

Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerabi

8.2
CVE-2025-4425

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad

8.2
CVE-2025-4423

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad

8.2
CVE-2025-4422

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad

8.2
CVE-2025-4421

The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad

7.0
CVE-2025-25011

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Pe

7.0
CVE-2025-0712

An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Pe

7.8
CVE-2025-43277

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15

8.8
CVE-2025-43270

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Son

7.8
CVE-2025-43256

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7

7.1
CVE-2025-43254

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Son

7.8
CVE-2025-43249

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS

7.8
CVE-2025-43248

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7.

7.1
CVE-2025-43239

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, ma

7.5
CVE-2025-43227

This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6

7.1
CVE-2025-43224

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18

7.5
CVE-2025-43223

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6,

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started