Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 679/1469
8.1
CVE-2025-30391

Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.

8.7
CVE-2025-30389

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

8.5
CVE-2025-21416

Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

8.5
CVE-2025-46342

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it

7.5
CVE-2025-27409

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into

8.8
CVE-2025-27134

Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into

8.8
CVE-2025-4120

A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been classified as critical. Affected is the function s

8.8
CVE-2025-4116

A vulnerability, which was classified as critical, has been found in Netgear JWNR2000v2 1.0.0.11. Affected by this issue

8.8
CVE-2025-4115

A vulnerability classified as critical was found in Netgear JWNR2000v2 1.0.0.11. Affected by this vulnerability is the f

7.2
CVE-2025-45020

A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing

7.1
CVE-2025-3395

Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB A

7.8
CVE-2025-3394

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automat

8.8
CVE-2025-4114

A vulnerability classified as critical has been found in Netgear JWNR2000v2 1.0.0.11. Affected is the function check_lan

8.8
CVE-2025-24351

A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (

7.1
CVE-2025-24350

A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenti

7.1
CVE-2025-24349

A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat

7.5
CVE-2025-24346

A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivil

7.3
CVE-2025-4112

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability

7.1
CVE-2025-24338

A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated

7.3
CVE-2025-4108

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un

7.8
CVE-2025-4125

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacke

7.8
CVE-2025-4124

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacke

7.8
CVE-2025-22884

Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an

7.8
CVE-2025-22883

Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacke

7.8
CVE-2025-22882

Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an

7.5
CVE-2025-30202

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and p

8.6
CVE-2025-29906

Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementatio

8.2
CVE-2025-3501

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is ski

7.5
CVE-2024-57698

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with

7.3
CVE-2025-4079

A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown fun

7.3
CVE-2025-4074

A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected

7.6
CVE-2025-46349

YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file uplo

7.3
CVE-2025-4073

A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an u

8.8
CVE-2025-45956

A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows a

8.0
CVE-2025-23181

CWE-250: Execution with Unnecessary Privileges

8.0
CVE-2025-23180

CWE-250: Execution with Unnecessary Privileges

7.3
CVE-2025-4071

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vuln

7.3
CVE-2025-4070

A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects

7.5
CVE-2025-40619

Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could all

8.8
CVE-2025-32354

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL

7.6
CVE-2025-23178

CWE-923: Improper Restriction of Communication Channel to Intended Endpoints

7.6
CVE-2025-23177

CWE-427: Uncontrolled Search Path Element

7.3
CVE-2025-4066

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affect

7.3
CVE-2025-4065

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerabi

8.1
CVE-2025-4093

Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and

8.1
CVE-2025-4091

Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs

7.1
CVE-2025-4085

An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive

8.8
CVE-2025-2817

Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man

7.3
CVE-2025-4060

A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affe

7.3
CVE-2025-4058

A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an un

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started