Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 619/1469
8.8
CVE-2025-25271

An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configura

8.4
CVE-2025-25269

An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc

8.8
CVE-2025-25268

An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting

7.8
CVE-2025-24006

A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges

7.8
CVE-2025-24005

A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t

8.2
CVE-2025-24003

An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying

8.8
CVE-2025-7327

The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu

7.3
CVE-2025-7165

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected

7.3
CVE-2025-7164

A vulnerability has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affe

7.3
CVE-2025-7160

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. This affects an unknown p

7.3
CVE-2025-7157

A vulnerability was found in code-projects Online Note Sharing 1.0. It has been classified as critical. Affected is an u

8.8
CVE-2025-20686

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

8.8
CVE-2025-20685

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

7.5
CVE-2025-7146

The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a

7.3
CVE-2025-7155

A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects

8.1
CVE-2025-42959

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extract

8.1
CVE-2025-42953

SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting

7.7
CVE-2025-42952

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta

7.3
CVE-2025-7147

A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by

7.5
CVE-2025-53539

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr

8.1
CVE-2025-53536

Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker

7.3
CVE-2025-7136

A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affe

7.5
CVE-2025-53531

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT

7.5
CVE-2025-53530

WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT

8.2
CVE-2025-36014

IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access

7.5
CVE-2024-25177

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which l

7.3
CVE-2025-7135

A vulnerability, which was classified as critical, has been found in Campcodes Online Recruitment Management System 1.0.

7.3
CVE-2025-7134

A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili

8.8
CVE-2025-53376

Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an

7.5
CVE-2025-52492

A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz,

7.5
CVE-2025-48367

Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP p

7.0
CVE-2025-32023

Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19,

7.5
CVE-2025-26780

An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che

7.3
CVE-2025-7132

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this is

7.5
CVE-2025-6807

Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability a

7.5
CVE-2025-6806

Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows r

7.5
CVE-2025-6804

Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulner

7.5
CVE-2025-6803

Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerabilit

7.5
CVE-2025-6801

Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability

7.5
CVE-2025-6800

Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerabili

7.5
CVE-2025-6799

Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability

7.5
CVE-2025-6797

Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability

7.5
CVE-2025-6796

Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability al

7.5
CVE-2025-6795

Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability

7.5
CVE-2025-6714

MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete dat

7.7
CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization d

7.8
CVE-2025-6663

GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows

8.1
CVE-2025-5987

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust th

7.3
CVE-2025-7131

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this

7.3
CVE-2025-7130

A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started