Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 701/1469
7.8
CVE-2025-2288

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write

7.8
CVE-2025-2287

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw

7.8
CVE-2025-2286

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw

7.8
CVE-2025-2285

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw

8.8
CVE-2025-1095

IBM Personal Communications v14 and v15 include a Windows service that is vulnerable to local privilege escalation (LPE)

8.6
CVE-2025-32406

An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows rem

8.2
CVE-2025-22466

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica

7.2
CVE-2025-22461

SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticate

7.8
CVE-2025-22458

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated atta

7.5
CVE-2025-30151

Shopware is an open commerce platform. It's possible to pass long passwords that leads to Denial Of Service via forms in

7.2
CVE-2025-25254

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb ver

7.2
CVE-2024-54024

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

7.5
CVE-2024-26013

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS versio

7.5
CVE-2023-37930

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilitie

8.3
CVE-2025-29986

Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intend

8.8
CVE-2025-2807

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installa

8.8
CVE-2025-3064

The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and

7.8
CVE-2025-22015

In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migratio

7.3
CVE-2025-22013

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unconditionally save+flush host FPSIMD/

8.8
CVE-2025-22012

In the Linux kernel, the following vulnerability has been resolved: Revert "arm64: dts: qcom: sdm845: Affirm IDR0.CCTW

8.6
CVE-2024-41793

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

8.6
CVE-2024-41792

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

7.3
CVE-2024-41791

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

7.5
CVE-2025-3431

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in

7.7
CVE-2025-30014

SAP Capital Yield Tax Management has directory traversal vulnerability due to insufficient path validation. This could a

7.7
CVE-2025-27428

Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using

8.5
CVE-2025-23186

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function

8.8
CVE-2025-20946

Improper handling of exceptional conditions in pairing specific bluetooth devices in Galaxy Watch Bluetooth pairing prio

8.8
CVE-2025-20936

Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to

7.3
CVE-2025-3401

A vulnerability has been found in ESAFENET CDG 5.6.3.154.205_20250114 and classified as critical. This vulnerability aff

7.3
CVE-2025-3400

A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. This affects an unk

7.3
CVE-2025-3399

A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.6.3.154.205_20250114. Affected by th

8.8
CVE-2025-2526

The Streamit theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i

8.8
CVE-2025-2525

The Streamit theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'st_

8.1
CVE-2025-32409

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signe

8.6
CVE-2025-0942

The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an

7.3
CVE-2025-3384

A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Aff

7.3
CVE-2025-3383

A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical.

7.5
CVE-2025-32034

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th

7.5
CVE-2025-32033

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th

7.5
CVE-2025-32032

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph th

7.5
CVE-2025-32031

Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to

7.5
CVE-2025-32030

Apollo Gateway provides utilities for combining multiple GraphQL microservices into a single GraphQL endpoint. Prior to

7.5
CVE-2025-31496

apollo-compiler is a query-based compiler for the GraphQL query language. Prior to 1.27.0, a vulnerability in Apollo Com

7.3
CVE-2025-3380

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. Affected by this issue is s

7.3
CVE-2025-3379

A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. Affected by this vulnerability is an unknown

7.3
CVE-2025-3378

A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the

7.3
CVE-2025-3377

A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown proc

7.3
CVE-2025-3376

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow

7.3
CVE-2025-3375

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started