Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 762/1469
7.3
CVE-2025-0509

A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with anoth

8.8
CVE-2025-23058

A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authe

7.5
CVE-2025-24648

Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Pr

7.1
CVE-2025-24602

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain C

7.1
CVE-2025-24599

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software

7.1
CVE-2025-24598

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails

7.1
CVE-2025-23645

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide

7.1
CVE-2025-22794

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ianhaycox World Cu

8.5
CVE-2025-22700

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele

7.2
CVE-2024-23690

The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac

8.8
CVE-2025-1014

Certificate length was not properly checked when added to a certificate store. In practice only trusted data was process

7.5
CVE-2025-1012

A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135,

8.8
CVE-2025-1011

A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage t

8.8
CVE-2025-1010

An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash.

8.8
CVE-2025-23015

Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES

8.8
CVE-2024-40891 KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le

8.8
CVE-2024-40890 KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL

7.5
CVE-2025-22205

Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension fo

7.0
CVE-2025-20890

Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to e

7.0
CVE-2025-20888

Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local

7.0
CVE-2025-20882

Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows

7.0
CVE-2025-20881

Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1

7.2
CVE-2024-10239

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin

7.2
CVE-2024-10238

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo

7.2
CVE-2024-10237

There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker

7.1
CVE-2024-13330

The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the

7.1
CVE-2024-13329

The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p

8.8
CVE-2025-24958

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio

8.8
CVE-2025-24902

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio

8.8
CVE-2025-24901

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio

7.8
CVE-2024-35177

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin

8.8
CVE-2025-24962

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands v

8.7
CVE-2025-24960

Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user

7.5
CVE-2025-24899

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where

7.5
CVE-2025-22918

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the us

7.5
CVE-2024-57451

ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which

8.1
CVE-2024-56903

Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against

7.5
CVE-2024-56902

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which

8.8
CVE-2024-56901

A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha

8.8
CVE-2024-56898

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p

7.5
CVE-2024-34897

Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.

7.5
CVE-2024-34896

An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected f

8.8
CVE-2023-52163 KEV

Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects

8.8
CVE-2025-25064

SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10

7.5
CVE-2024-57669

Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive inf

7.5
CVE-2024-57452

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows

7.5
CVE-2024-56921

An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF

8.8
CVE-2024-12859

The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu

7.6
CVE-2024-12511

With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This

7.3
CVE-2024-57238

Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started