Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 656/1469
7.3
CVE-2025-5076

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown

7.3
CVE-2025-5075

A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is

7.8
CVE-2025-46714

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve

7.8
CVE-2025-46713

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve

7.2
CVE-2025-3945

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Fram

7.2
CVE-2025-3944

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara

7.7
CVE-2025-3937

Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux

7.0
CVE-2025-2272

Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, H

7.3
CVE-2025-5074

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown functio

7.3
CVE-2025-5073

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some u

8.3
CVE-2025-41403

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching

8.3
CVE-2025-3836

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon ev

8.8
CVE-2024-25010

Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp

7.6
CVE-2025-4123

A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire

8.8
CVE-2025-3887

GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows

7.5
CVE-2025-3884

Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac

8.8
CVE-2025-3883

eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw

8.8
CVE-2025-3882

eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability

8.8
CVE-2025-3881

eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all

8.8
CVE-2025-3486

Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac

7.8
CVE-2025-3483

MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil

7.8
CVE-2025-3482

MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil

7.8
CVE-2025-3481

MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil

7.8
CVE-2025-2759

GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta

8.8
CVE-2025-34025

The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerab

7.3
CVE-2025-5057

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue

7.3
CVE-2025-5056

A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vu

7.5
CVE-2025-47947

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions

7.5
CVE-2025-34026 KEV

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy

7.3
CVE-2025-5053

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is

7.3
CVE-2025-5052

A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno

7.2
CVE-2025-45753

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary P

7.2
CVE-2025-44040

An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash functi

7.3
CVE-2025-5051

A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th

7.3
CVE-2025-5050

A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown pr

7.3
CVE-2025-5049

A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unkn

7.2
CVE-2025-45752

A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting t

8.8
CVE-2025-48063

XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc

7.5
CVE-2025-48060

jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio

7.5
CVE-2025-47291

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,

7.3
CVE-2025-5032

A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu

7.5
CVE-2025-4416

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio

8.6
CVE-2025-20152

A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen

7.1
CVE-2025-20113

A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges

8.8
CVE-2025-4008 KEV

The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer

8.6
CVE-2025-48207

The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.

8.6
CVE-2025-48205

The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.

8.6
CVE-2025-48201

The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.

8.4
CVE-2025-27998

An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe

8.4
CVE-2025-27997

An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started