Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 607/1469
7.6
CVE-2025-6023

An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vuln

7.8
CVE-2025-38349

In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still

7.5
CVE-2025-7438

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid

8.8
CVE-2025-6718

The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX

8.8
CVE-2025-6813

The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi

8.8
CVE-2025-3740

The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up

7.3
CVE-2025-7765

A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi

7.3
CVE-2025-7764

A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i

8.8
CVE-2025-7762

A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some

8.8
CVE-2025-7758

A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected b

7.1
CVE-2025-7397

A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interfa

7.3
CVE-2025-7757

A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is

7.3
CVE-2025-7753

A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. Th

7.3
CVE-2025-7752

A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by

7.3
CVE-2025-7751

A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affect

8.8
CVE-2025-7433

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and o

7.4
CVE-2025-6248

A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sen

7.8
CVE-2025-6232

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at

7.8
CVE-2025-6231

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at

7.8
CVE-2025-3753

A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS dist

7.1
CVE-2025-23270

NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exp

8.5
CVE-2025-23267

NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could

7.0
CVE-2025-1700

A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that coul

7.8
CVE-2025-0886

An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe

7.8
CVE-2024-41921

A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff

7.8
CVE-2024-41148

A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff

7.8
CVE-2024-39835

A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af

7.8
CVE-2024-39289

A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di

7.3
CVE-2025-7750

A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff

7.5
CVE-2025-7472

A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a loc

7.5
CVE-2025-53817

7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to vers

7.5
CVE-2025-53816

7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to m

8.8
CVE-2024-13972

A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.

7.3
CVE-2025-7749

A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0

8.8
CVE-2025-7747

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle

7.6
CVE-2025-23263

NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es

8.1
CVE-2024-32323

SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information v

7.5
CVE-2025-7338

Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1

8.8
CVE-2023-47356

Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via th

8.1
CVE-2023-41566

OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend

8.8
CVE-2025-54062

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54061

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54060

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-54058

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.8
CVE-2025-53946

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

7.5
CVE-2025-1713

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream brid

7.5
CVE-2025-7735

The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a

7.5
CVE-2025-40777

If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set

7.3
CVE-2025-37107

An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

7.3
CVE-2025-37106

An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started