Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 475/1469
8.8
CVE-2025-66434

An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th

8.2
CVE-2025-65742

An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to

8.7
CVE-2025-11393

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of

8.8
CVE-2025-60786

A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb

8.3
CVE-2024-44599

FNT Command 13.4.0 is vulnerable to Directory Traversal.

8.8
CVE-2024-44598

FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.

7.5
CVE-2025-14383

The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param

8.2
CVE-2025-65781

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upl

8.8
CVE-2025-65780

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated

7.5
CVE-2025-65779

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticate

8.1
CVE-2025-65778

An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attac

7.3
CVE-2025-14711

A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability a

7.3
CVE-2025-14710

A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects

7.7
CVE-2025-14022

LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an

7.5
CVE-2025-14712

Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil

8.1
CVE-2025-14549

In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR

7.1
CVE-2025-13355

The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t

7.1
CVE-2025-12684

The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t

7.3
CVE-2025-14704

A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshel

8.1
CVE-2025-67900

NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.

7.3
CVE-2025-14673

A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as

7.3
CVE-2025-14672

A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the

7.3
CVE-2025-14668

A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of th

7.3
CVE-2025-14667

A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown

7.3
CVE-2025-14666

A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of

7.3
CVE-2025-14664

A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing o

7.3
CVE-2025-14661

A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown func

8.8
CVE-2025-14659

A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the c

8.8
CVE-2025-14656

A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedW

8.8
CVE-2025-14655

A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer o

8.8
CVE-2025-14654

A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of th

7.3
CVE-2025-14653

A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the fil

7.3
CVE-2025-14652

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of

7.3
CVE-2025-14650

A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakesho

7.3
CVE-2025-14649

A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown fun

7.3
CVE-2025-14647

A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /ad

7.3
CVE-2025-14646

A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown functio

7.3
CVE-2025-14645

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of

7.5
CVE-2025-13126

The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame

7.0
CVE-2025-67896

Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow becau

7.3
CVE-2025-14644

A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown functio

7.3
CVE-2025-14643

A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown funct

7.3
CVE-2025-14640

A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function o

7.3
CVE-2025-14639

A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file

7.3
CVE-2025-14638

A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects som

7.3
CVE-2025-14637

A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown

7.3
CVE-2025-14623

A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown proc

7.3
CVE-2025-14622

A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unkn

7.3
CVE-2025-14621

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the

7.3
CVE-2025-14620

A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started