Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 648/1469
8.8
CVE-2025-5629

A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function

7.3
CVE-2025-5626

A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected

7.3
CVE-2025-5625

A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been rated as critical. This

7.3
CVE-2025-5621

A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. Affected by this vulnerability is

7.3
CVE-2025-5620

A vulnerability, which was classified as critical, was found in D-Link DIR-816 1.10CNB05. Affected is the function setip

8.8
CVE-2025-5619

A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. This issue affects the function

7.1
CVE-2025-46341

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, when the server is using HTTP auth via reverse p

8.8
CVE-2025-5609

A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the functi

8.8
CVE-2025-5608

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formsetreboott

8.8
CVE-2025-5607

A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function form

7.5
CVE-2025-31134

FreshRSS is a self-hosted RSS feed aggregator. Prior to version 1.26.2, an attacker can gain additional information abou

7.5
CVE-2025-22243

VMware NSX Manager UI is vulnerable to a stored Cross-Site Scripting (XSS) attack due to improper input validation.

7.3
CVE-2025-5604

A vulnerability was found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this issue

7.3
CVE-2025-5603

A vulnerability has been found in Campcodes Hospital Management System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-5602

A vulnerability, which was classified as critical, was found in Campcodes Hospital Management System 1.0. Affected is an

7.3
CVE-2025-5599

A vulnerability classified as critical was found in PHPGurukul Student Result Management System 1.3. This vulnerability

7.3
CVE-2025-5596

A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi

7.3
CVE-2025-5595

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. This issue affects some unknown proces

8.8
CVE-2025-20261

A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, U

8.7
CVE-2025-20163

A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticat

7.3
CVE-2025-5594

A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. This vulnerability affects unknow

7.3
CVE-2025-5593

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o

8.2
CVE-2025-29093

File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary cod

7.3
CVE-2025-5592

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is

7.3
CVE-2025-48961

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec

7.8
CVE-2025-27811

A local privilege escalation in the razer_elevation_service.exe in Razer Synapse 4 through 4.0.86.2502180127 allows a lo

7.5
CVE-2025-30415

Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protec

7.8
CVE-2025-5601

Column handling crashes in Wireshark 4.4.0 to 4.4.6 and 4.2.0 to 4.2.12 allows denial of service via packet injection or

7.3
CVE-2025-5583

A vulnerability classified as critical has been found in CodeAstro Real Estate Management System 1.0. Affected is an unk

7.5
CVE-2018-25112

An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected

7.3
CVE-2025-5581

A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnera

7.3
CVE-2025-5580

A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affec

7.3
CVE-2025-5579

A vulnerability was found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by th

7.3
CVE-2025-5578

A vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected

7.3
CVE-2025-5577

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System 1.3. Affect

7.3
CVE-2025-5576

A vulnerability, which was classified as critical, has been found in PHPGurukul Dairy Farm Shop Management System 1.3. T

8.8
CVE-2025-5482

The Sunshine Photo Cart: Free Client Photo Galleries for Photographers plugin for WordPress is vulnerable to privilege e

7.3
CVE-2025-47728

Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att

7.3
CVE-2025-47727

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack

7.3
CVE-2025-47726

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack

7.3
CVE-2025-47725

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack

7.3
CVE-2025-47724

Delta Electronics CNCSoft lacks proper validation of the user-supplied file. If a user opens a malicious file, an attack

8.8
CVE-2024-13967

This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by

7.3
CVE-2025-5575

A vulnerability classified as critical was found in PHPGurukul Dairy Farm Shop Management System 1.3. This vulnerability

7.3
CVE-2025-5574

A vulnerability classified as critical has been found in PHPGurukul Dairy Farm Shop Management System 1.3. This affects

8.8
CVE-2025-5572

A vulnerability was found in D-Link DCS-932L 2.18.01. It has been declared as critical. Affected by this vulnerability i

7.3
CVE-2025-5562

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been rated as critical. Affected by

7.3
CVE-2025-5561

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected

7.3
CVE-2024-31127

An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker t

7.3
CVE-2025-5560

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been classified as critical. Affecte

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started