Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 202/1469
7.1
CVE-2025-69151

Unauthenticated Cross Site Scripting (XSS) in Grand Car Rental <= 3.7 versions.

8.1
CVE-2025-69150

Unauthenticated Local File Inclusion in Medeus <= 1.14 versions.

8.1
CVE-2025-69149

Unauthenticated Local File Inclusion in Top Dog <= 1.0.5 versions.

8.1
CVE-2025-69148

Unauthenticated Local File Inclusion in Quirky <= 1.23 versions.

8.1
CVE-2025-69147

Unauthenticated Local File Inclusion in Putter <= 1.17 versions.

8.1
CVE-2025-69146

Unauthenticated Local File Inclusion in Dom <= 1.24 versions.

8.1
CVE-2025-69145

Unauthenticated Local File Inclusion in Gat <= 1.16 versions.

8.1
CVE-2025-69143

Unauthenticated Local File Inclusion in Mission <= 1.22 versions.

8.1
CVE-2025-69142

Unauthenticated Local File Inclusion in Abelle <= 1.22 versions.

8.1
CVE-2025-69141

Unauthenticated Local File Inclusion in Kelly Young <= 1.1.0 versions.

8.6
CVE-2025-69139

Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.

8.8
CVE-2025-69138

Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.

8.1
CVE-2025-69136

Unauthenticated Local File Inclusion in Wanium <= 1.9.8 versions.

8.5
CVE-2025-69135

Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.

7.5
CVE-2025-69131

Unauthenticated Arbitrary File Download in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 ve

8.1
CVE-2025-69125

Unauthenticated Local File Inclusion in Food Drop <= 1.3 versions.

8.1
CVE-2025-69124

Unauthenticated Local File Inclusion in Especio <= 1.0 versions.

8.1
CVE-2025-69121

Unauthenticated Local File Inclusion in Deliciosa <= 1.10.0 versions.

8.1
CVE-2025-69119

Unauthenticated Local File Inclusion in Corbesier <= 1.15.0 versions.

8.1
CVE-2025-69118

Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions.

8.1
CVE-2025-69117

Unauthenticated Local File Inclusion in Ingenioso <= 1.14.0 versions.

8.1
CVE-2025-69116

Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions.

8.1
CVE-2025-69114

Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions.

8.1
CVE-2025-69113

Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions.

8.1
CVE-2025-69112

Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions.

8.1
CVE-2025-69110

Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.

8.1
CVE-2025-69109

Unauthenticated Local File Inclusion in Raider Spirit <= 1.1.2 versions.

8.1
CVE-2025-69107

Unauthenticated Local File Inclusion in Rosaleen <= 2.8 versions.

8.1
CVE-2025-69105

Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions.

7.1
CVE-2025-69104

Unauthenticated Cross Site Scripting (XSS) in Qreatix <= 1.9.4 versions.

7.5
CVE-2025-69103

Subscriber Arbitrary Content Deletion in Brikk <= 3.0.0 versions.

7.7
CVE-2025-60223

Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.

8.1
CVE-2025-60085

Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.

8.8
CVE-2025-59563

Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.

7.1
CVE-2025-59560

Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.

8.1
CVE-2025-58954

Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.

8.1
CVE-2025-58953

Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.

8.1
CVE-2025-58952

Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.

8.1
CVE-2025-58924

Unauthenticated Local File Inclusion in Geya <= 1.15 versions.

7.5
CVE-2025-49403

Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3.0.2 versions.

7.8
CVE-2025-48643

In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local

8.0
CVE-2025-48640

In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. T

7.8
CVE-2025-48617

In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass.

7.1
CVE-2025-31013

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allow

7.1
CVE-2024-49269

Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.

8.3
CVE-2024-32949

Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Con

7.5
CVE-2024-32729

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversatio

7.4
CVE-2026-48294

Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclo

7.2
CVE-2026-46976

Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations).

7.5
CVE-2026-46974

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started