Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 652/1469
7.4
CVE-2025-5276

Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the

7.2
CVE-2025-31501

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.

7.2
CVE-2025-31500

Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.

7.2
CVE-2025-30087

Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramete

7.8
CVE-2025-32801

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea a

7.3
CVE-2025-4134

Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof o

8.8
CVE-2025-48734

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2.

8.6
CVE-2025-45997

Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can uploa

7.3
CVE-2025-5299

A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. Thi

7.3
CVE-2025-5298

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte

7.3
CVE-2025-5295

A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code

7.8
CVE-2025-1753

LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the impro

7.5
CVE-2025-5287

The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio

7.8
CVE-2025-25251

An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 th

8.8
CVE-2025-4800

The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati

8.8
CVE-2025-5280

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap

7.0
CVE-2025-5222

A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'su

8.8
CVE-2025-5063

Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit h

7.1
CVE-2025-45529

An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbit

7.3
CVE-2024-13966

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged

7.3
CVE-2025-5252

A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability af

7.3
CVE-2025-5251

A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unk

7.3
CVE-2025-5250

A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is so

7.3
CVE-2025-5249

A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulner

7.5
CVE-2024-49196

An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of

7.3
CVE-2025-5248

A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affect

8.4
CVE-2025-27700

There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of

7.3
CVE-2025-5247

A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function

7.3
CVE-2025-5246

A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability

8.2
CVE-2025-48383

Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses li

7.3
CVE-2025-48798

A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special

7.3
CVE-2025-48797

A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been

7.3
CVE-2025-48796

A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.AN

7.3
CVE-2025-5272

Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption a

7.5
CVE-2025-5270

In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed

8.1
CVE-2025-5269

Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption a

8.1
CVE-2025-5268

Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bu

7.5
CVE-2025-5262

A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder

8.8
CVE-2025-5117

The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of

7.5
CVE-2025-41653

An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionalit

7.5
CVE-2025-41650

An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt

7.5
CVE-2025-41649

An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer

7.5
CVE-2024-38866

Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection

7.3
CVE-2025-5231

A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability

7.3
CVE-2025-5230

A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unkn

7.3
CVE-2025-5229

A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by

8.8
CVE-2025-5228

A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function

7.3
CVE-2025-5227

A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown proces

7.3
CVE-2025-5226

A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknow

7.3
CVE-2025-5225

A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affect

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started