Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 598/1469
7.5
CVE-2025-8194

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar

7.1
CVE-2025-50487

Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy

7.1
CVE-2025-50484

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to

7.5
CVE-2025-50492

Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo

7.1
CVE-2025-50491

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v

7.5
CVE-2025-50489

Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System

7.1
CVE-2025-50488

Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst

7.7
CVE-2025-54531

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

7.5
CVE-2025-54530

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

7.5
CVE-2025-50494

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v

7.5
CVE-2025-50493

Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S

7.5
CVE-2025-50490

Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst

7.8
CVE-2025-2297

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challe

7.5
CVE-2024-49342

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacke

8.7
CVE-2025-8279

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query

7.5
CVE-2025-4056

A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a progr

7.3
CVE-2025-8274

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this

8.8
CVE-2025-5997

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro:

7.1
CVE-2025-38497

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string

8.8
CVE-2025-38495

In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can c

7.8
CVE-2025-38494

In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw

8.2
CVE-2025-38491

In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision a

7.8
CVE-2025-38486

In the Linux kernel, the following vulnerability has been resolved: soundwire: Revert "soundwire: qcom: Add set_channel

7.8
CVE-2025-38485

In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8

7.8
CVE-2025-38484

In the Linux kernel, the following vulnerability has been resolved: iio: backend: fix out-of-bound write The buffer is

7.1
CVE-2025-38483

In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When

7.1
CVE-2025-38482

In the Linux kernel, the following vulnerability has been resolved: comedi: das6402: Fix bit shift out of bounds When

7.8
CVE-2025-38478

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions

7.8
CVE-2025-38477

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggre

7.8
CVE-2025-38475

In the Linux kernel, the following vulnerability has been resolved: smc: Fix various oops due to inet_sock type confusi

7.8
CVE-2025-38470

In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix VLAN 0 refcount imbalance of togglin

7.3
CVE-2025-8273

A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown

7.3
CVE-2025-8272

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s

7.3
CVE-2025-8271

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerabilit

7.3
CVE-2025-8270

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an

7.3
CVE-2025-8269

A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue i

7.3
CVE-2025-8261

A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgr

7.3
CVE-2025-8259

A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_Da

8.2
CVE-2025-8267

Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete

7.3
CVE-2025-8255

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s

7.3
CVE-2025-8253

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an

7.3
CVE-2025-8252

A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue i

7.3
CVE-2025-8251

A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vu

7.3
CVE-2025-8250

A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1.0. Affected is an u

7.3
CVE-2025-8249

A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue

7.3
CVE-2025-8248

A vulnerability classified as critical was found in code-projects Online Ordering System 1.0. This vulnerability affects

8.8
CVE-2025-8246

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is

8.8
CVE-2025-8245

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulne

8.8
CVE-2025-8244

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unkno

8.8
CVE-2025-8243

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unkno

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started