Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 668/1469
8.0
CVE-2025-24223

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, mac

7.8
CVE-2025-1079

Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

7.6
CVE-2024-4982

A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted gi

7.6
CVE-2024-4981

A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links

7.5
CVE-2025-46740

An authenticated user without user administrative permissions could change the administrator Account Name.

8.1
CVE-2025-46739

An unauthenticated user could discover account credentials via a brute-force attack without rate limiting

7.5
CVE-2025-3632

IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardw

7.4
CVE-2025-46737

SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data g

8.8
CVE-2025-46610

ARTEC EMA Mail 6.92 allows CSRF.

7.5
CVE-2025-45835

A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_

7.5
CVE-2025-47270

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a

8.5
CVE-2025-32390

EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Know

7.5
CVE-2025-3496

An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluet

8.8
CVE-2025-4561

The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to up

7.3
CVE-2025-4554

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Th

7.3
CVE-2025-4553

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by

7.3
CVE-2025-4550

A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0

7.3
CVE-2025-4549

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affect

7.3
CVE-2025-4548

A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn

7.3
CVE-2025-4543

A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the fil

7.0
CVE-2025-4540

A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects so

7.0
CVE-2025-4539

A vulnerability was found in Hainan ToDesk 4.7.6.3. It has been declared as critical. This vulnerability affects unknown

7.0
CVE-2025-4532

A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19

7.0
CVE-2025-4525

A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue

8.8
CVE-2025-47817

In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.

7.3
CVE-2025-4509

A vulnerability, which was classified as critical, has been found in PHPGurukul e-Diary Management System 1.0. This issu

7.3
CVE-2025-4508

A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects

7.3
CVE-2025-4507

A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn

7.3
CVE-2025-4506

A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this

7.3
CVE-2025-4505

A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. Affe

7.3
CVE-2025-4504

A vulnerability was found in SourceCodester Online College Library System 1.0. It has been classified as critical. Affec

7.8
CVE-2023-53145

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio

7.3
CVE-2025-4503

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som

7.3
CVE-2025-4502

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit

7.5
CVE-2025-1752

A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_i

8.8
CVE-2025-3876

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insuff

8.8
CVE-2025-2158

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L

8.8
CVE-2025-4496

A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It ha

7.5
CVE-2025-1137

IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privil

7.1
CVE-2025-47424

Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set,

7.3
CVE-2025-4494

A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin

7.3
CVE-2025-4492

A vulnerability, which was classified as critical, has been found in Campcodes Online Food Ordering System 1.0. This iss

7.3
CVE-2025-4491

A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affect

7.3
CVE-2025-4490

A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn

7.3
CVE-2025-4489

A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this

7.8
CVE-2025-4447

In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by m

8.3
CVE-2025-47269

code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted

7.3
CVE-2025-4488

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this

7.3
CVE-2025-4487

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. Affected is an

7.3
CVE-2025-4486

A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. This issue affects some

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started