Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 674/1469
7.5
CVE-2025-46728

cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enf

7.8
CVE-2025-2509

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address acc

7.3
CVE-2025-4300

A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unkn

8.8
CVE-2025-4299

A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been rated as critical. This issue affects the funct

8.8
CVE-2025-4298

A vulnerability was found in Tenda AC1206 up to 15.03.06.23. It has been declared as critical. This vulnerability affect

7.3
CVE-2025-4297

A vulnerability was found in PHPGurukul Men Salon Management System 2.0. It has been classified as critical. This affect

7.3
CVE-2025-4290

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk

7.3
CVE-2025-4289

A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of t

7.3
CVE-2025-4288

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com

7.2
CVE-2025-46731

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch pri

7.5
CVE-2025-45617

Incorrect access control in the component /user/list of production_ssm v0.0.1-SNAPSHOT allows attackers to access sensit

7.5
CVE-2025-45614

Incorrect access control in the component /api/user/manager of One v1.0 allows attackers to access sensitive information

7.5
CVE-2025-45613

Incorrect access control in the component /user/list of Shiro-Action v0.6 allows attackers to access sensitive informati

7.5
CVE-2025-45610

Incorrect access control in the component /scheduleLog/info/1 of PassJava-Platform v3.0.0 allows attackers to access sen

7.5
CVE-2025-45609

Incorrect access control in the doFilter function of kob latest v1.0.0-SNAPSHOT allows attackers to access sensitive inf

7.5
CVE-2025-45608

Incorrect access control in the /system/user/findUserList API of Xinguan v0.0.1-SNAPSHOT allows attackers to access sens

7.3
CVE-2025-4283

A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue

8.8
CVE-2025-4279

The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat

7.2
CVE-2025-46340

Misskey is an open source, federated social media platform. Starting in version 12.0.0 and prior to version 2025.4.1, du

8.8
CVE-2025-4096

Heap buffer overflow in HTML in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentially exploit he

8.8
CVE-2025-4050

Out of bounds memory access in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker who convinced

7.5
CVE-2025-45237

Incorrect access control in the component /config/download of DBSyncer v2.0.6 allows attackers to access the JSON file c

7.7
CVE-2025-45242

Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method

7.8
CVE-2025-0217

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A loc

8.8
CVE-2025-45322

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the

8.8
CVE-2025-45321

kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.ph

8.1
CVE-2025-28062

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allow

7.2
CVE-2025-27920 KEV

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us

7.8
CVE-2024-58237

In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet poi

7.8
CVE-2024-58100

In the Linux kernel, the following vulnerability has been resolved: bpf: check changes_pkt_data property for extension

7.8
CVE-2024-58098

In the Linux kernel, the following vulnerability has been resolved: bpf: track changes_pkt_data property for global fun

7.0
CVE-2025-4272

A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is

7.3
CVE-2025-4266

A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. Affected by thi

7.3
CVE-2025-4265

A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this v

7.3
CVE-2025-4264

A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a

7.3
CVE-2025-4263

A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This iss

7.3
CVE-2025-4262

A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been declared as critical. This

7.0
CVE-2025-20671

In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of priv

7.8
CVE-2025-20668

In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr

7.5
CVE-2025-20667

In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote informat

7.5
CVE-2025-20666

In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if

7.3
CVE-2025-4255

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com

7.3
CVE-2025-4254

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno

7.3
CVE-2025-4253

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is

7.3
CVE-2025-4252

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function

7.3
CVE-2025-4251

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. This issue affects some unknown processi

7.3
CVE-2025-4250

A vulnerability was found in code-projects Nero Social Networking Site 1.0. It has been classified as critical. This aff

7.3
CVE-2025-4249

A vulnerability was found in PHPGurukul e-Diary Management System 1.0 and classified as critical. Affected by this issue

8.1
CVE-2025-47245

In BlueWave Checkmate through 2.0.2 before d4a6072, an invite request can be modified to specify a privileged role.

7.3
CVE-2025-47244

Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer,

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started