Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 638/1469
8.8
CVE-2025-6143

A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an

8.8
CVE-2025-6138

A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the fun

8.8
CVE-2025-6137

A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiSche

7.0
CVE-2025-32797

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts functi

7.3
CVE-2025-6132

A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unkno

7.4
CVE-2025-6177

Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local

8.8
CVE-2025-6130

A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue

8.8
CVE-2025-6129

A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects

8.8
CVE-2025-6128

A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknow

7.5
CVE-2025-49795

A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an

7.5
CVE-2025-49125

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or Pos

8.4
CVE-2025-49124

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer fo

7.5
CVE-2025-48988

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat:

7.5
CVE-2025-48976

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons Fil

7.5
CVE-2025-3526

SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 2

7.3
CVE-2025-6124

A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects so

7.5
CVE-2025-3602

Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA thr

7.8
CVE-2025-36632

In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c

7.3
CVE-2025-6123

A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerabili

8.5
CVE-2025-5689

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir

7.3
CVE-2025-6118

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affe

7.3
CVE-2025-6117

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnera

7.3
CVE-2025-6116

A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affec

8.8
CVE-2025-6115

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function

8.8
CVE-2025-6114

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is

8.8
CVE-2025-40728

SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr

8.8
CVE-2025-6113

A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvse

8.8
CVE-2025-6112

A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the functi

8.7
CVE-2025-4987

A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Rel

8.8
CVE-2025-6111

A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function f

8.8
CVE-2025-6110

A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the

8.8
CVE-2025-6104

A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects

8.8
CVE-2025-6103

A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affecte

8.8
CVE-2025-6102

A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnera

7.3
CVE-2025-6095

A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unk

7.6
CVE-2025-5990

An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a

8.8
CVE-2025-6091

A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function Upd

8.8
CVE-2025-6090

A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function Updat

7.8
CVE-2025-1411

IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root d

8.1
CVE-2025-4200

The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusi

7.2
CVE-2025-5487

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP

7.2
CVE-2025-3234

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va

8.5
CVE-2025-33108

IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a

8.8
CVE-2025-25215

An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell

8.1
CVE-2025-24919

A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 p

8.8
CVE-2025-25050

An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior

8.8
CVE-2025-24922

A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior

8.4
CVE-2025-24311

An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.1

8.0
CVE-2025-49587

XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifi

8.8
CVE-2025-49586

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started