Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 680/1469
7.5
CVE-2025-3891

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to

7.5
CVE-2025-30194

When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by craftin

8.6
CVE-2024-58099

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_

8.8
CVE-2025-24252

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i

7.7
CVE-2025-24206

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i

7.3
CVE-2025-4039

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been rated as critical. Affected by this

7.3
CVE-2025-4034

A vulnerability classified as critical was found in projectworlds Online Examination System 1.0. Affected by this vulner

7.8
CVE-2025-3224

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr

8.8
CVE-2025-34491

GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attac

7.5
CVE-2025-31650

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority header

7.3
CVE-2025-4033

A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected

7.8
CVE-2025-34489

GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escal

7.3
CVE-2025-4031

A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnera

7.3
CVE-2025-4030

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This

7.3
CVE-2025-4028

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected

7.3
CVE-2025-4027

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected

7.3
CVE-2025-4026

A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.

7.2
CVE-2015-4582

The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: C

7.3
CVE-2025-4025

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne

7.3
CVE-2025-4024

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un

7.8
CVE-2025-23375

Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability

7.3
CVE-2025-4023

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff

7.3
CVE-2025-4020

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-4019

A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af447

7.3
CVE-2025-4014

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by

7.3
CVE-2025-4013

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected

7.8
CVE-2025-42598

Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when inst

7.5
CVE-2025-32470

A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availab

8.8
CVE-2025-4007

A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vuln

7.3
CVE-2025-22235

EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been crea

7.3
CVE-2025-4005

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue

7.3
CVE-2025-4004

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been declared as critical. This vu

7.3
CVE-2025-3998

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affec

8.8
CVE-2025-3993

A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown

8.8
CVE-2025-3992

A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects

8.8
CVE-2025-3991

A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown

8.1
CVE-2025-26692

Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Pa

8.8
CVE-2025-3990

A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this i

8.8
CVE-2025-3989

A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is a

8.8
CVE-2025-3988

A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown functio

7.2
CVE-2025-46657

Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.

7.3
CVE-2025-3976

A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affec

7.3
CVE-2025-3974

A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vuln

7.3
CVE-2025-3973

A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This a

7.3
CVE-2025-3972

A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. A

7.3
CVE-2025-3971

A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this v

8.1
CVE-2025-3886

An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition

7.3
CVE-2025-3963

A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue a

7.3
CVE-2025-3960

A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issu

7.7
CVE-2025-46580

There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt th

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started