Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 605/1469
7.8
CVE-2025-7227

INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows rem

7.8
CVE-2025-7226

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote

7.8
CVE-2025-7225

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote

7.8
CVE-2025-7224

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote

7.8
CVE-2025-7223

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote

7.8
CVE-2025-7222

Luxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remot

7.5
CVE-2025-51869

Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive inform

7.5
CVE-2025-51868

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive inf

7.5
CVE-2025-7962

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 cha

7.3
CVE-2025-7933

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects

7.5
CVE-2025-44652

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. Th

8.6
CVE-2025-36845

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side

7.3
CVE-2025-7931

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i

7.5
CVE-2025-7717

Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f

7.5
CVE-2025-44653

In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS atta

7.5
CVE-2025-44649

In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggres

7.3
CVE-2025-7930

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi

7.3
CVE-2025-7929

A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a

7.5
CVE-2025-44651

In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can c

7.5
CVE-2025-44650

In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf

7.3
CVE-2025-44647

In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the str

7.3
CVE-2025-7928

A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects som

7.2
CVE-2025-46123

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir

8.8
CVE-2025-46116

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir

8.8
CVE-2025-7382

A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjac

7.5
CVE-2025-4130

Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.

7.5
CVE-2025-4129

Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Iden

8.1
CVE-2024-13974

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead

7.1
CVE-2025-4040

Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Priv

7.5
CVE-2025-30192

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-EC

7.8
CVE-2025-41459

Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App St

8.8
CVE-2025-50151

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affe

7.5
CVE-2025-49656

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe

7.2
CVE-2025-41675

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati

7.2
CVE-2025-41674

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t

7.2
CVE-2025-41673

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to

7.5
CVE-2025-1469

Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted

8.8
CVE-2025-7344

The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges

8.4
CVE-2025-24938

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An at

7.2
CVE-2025-7917

WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attac

7.3
CVE-2025-7915

A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown function

8.8
CVE-2025-7914

A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is th

8.8
CVE-2025-7913

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the funct

8.8
CVE-2025-7912

A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affec

8.8
CVE-2025-7911

A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf

8.8
CVE-2025-7910

A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the f

8.8
CVE-2025-7909

A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function s

8.8
CVE-2025-7908

A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the

8.4
CVE-2025-54317

An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln

8.9
CVE-2025-47917

Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started