Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 620/1469
7.5
CVE-2023-51232

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive i

7.3
CVE-2025-7129

A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some

7.3
CVE-2025-7128

A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability

7.5
CVE-2025-6209

A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the

7.3
CVE-2025-7122

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been declared as critical. This vulnerabi

7.5
CVE-2025-6386

The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within t

7.2
CVE-2025-3466

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbi

7.5
CVE-2025-3262

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository,

7.5
CVE-2025-3225

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-

7.5
CVE-2025-3046

A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allo

7.1
CVE-2024-43334

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom

7.3
CVE-2025-7120

A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issu

7.3
CVE-2025-7119

A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this

8.8
CVE-2025-7118

A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affec

8.8
CVE-2025-7117

A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknow

8.8
CVE-2025-7116

A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of

7.3
CVE-2025-7115

A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr

7.3
CVE-2025-7114

A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri

7.3
CVE-2025-53473

Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulne

7.2
CVE-2025-7145

ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers wit

7.6
CVE-2025-53169

Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful e

8.1
CVE-2025-7097

A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This

7.5
CVE-2025-3108

A critical deserialization vulnerability exists in the run-llama/llama_index library's JsonPickleSerializer component, a

8.1
CVE-2025-7096

A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability aff

8.8
CVE-2025-7094

A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. Affected by this issue is the functi

8.8
CVE-2025-7093

A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. Affected by this vulnerability is

8.8
CVE-2025-7092

A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. This vulnerability affects the func

8.8
CVE-2025-7091

A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. Affected is the function formWl

8.8
CVE-2025-7090

A vulnerability, which was classified as critical, has been found in Belkin F9K1122 1.00.33. Affected by this issue is t

8.8
CVE-2025-7089

A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. This issue affects the function formWanT

8.8
CVE-2025-7088

A vulnerability, which was classified as critical, was found in Belkin F9K1122 1.00.33. This affects the function formPP

8.8
CVE-2025-7087

A vulnerability classified as critical was found in Belkin F9K1122 1.00.33. Affected by this vulnerability is the functi

8.8
CVE-2025-7086

A vulnerability classified as critical has been found in Belkin F9K1122 1.00.33. Affected is the function formPPTPSetup

8.8
CVE-2025-7085

A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. This issue affects the function form

8.8
CVE-2025-7084

A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. This vulnerability affects the fu

8.8
CVE-2025-7077

A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This a

7.8
CVE-2025-27446

Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listeni

7.5
CVE-2025-47227

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset me

7.5
CVE-2025-53603

In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo

8.1
CVE-2025-43711

Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upo

7.5
CVE-2025-53485

SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user

8.8
CVE-2025-53483

ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF toke

7.5
CVE-2025-53481

Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Al

7.8
CVE-2025-52496

Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may b

7.9
CVE-2025-46733

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte

7.8
CVE-2025-38234

In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======

7.8
CVE-2025-38233

In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatc

7.8
CVE-2025-38232

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and export

7.8
CVE-2025-38230

In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent

7.8
CVE-2025-38227

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started