Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 499/1469
7.3
CVE-2025-13242

A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processi

7.3
CVE-2025-13241

A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the fi

7.3
CVE-2025-13240

A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /

7.3
CVE-2025-13237

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of

7.5
CVE-2025-12482

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘s

7.3
CVE-2025-13235

A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the

7.3
CVE-2025-13233

A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown funct

7.3
CVE-2025-13203

A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code

7.3
CVE-2025-13201

A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown

8.8
CVE-2025-13191

A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the fil

8.8
CVE-2025-13190

A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the

8.8
CVE-2025-13189

A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena

8.4
CVE-2025-9317

The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f

7.4
CVE-2025-64309

The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut

7.5
CVE-2025-62765

General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a

7.5
CVE-2025-59780

General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all

8.2
CVE-2025-55034

General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow a

7.5
CVE-2025-63891

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote u

7.5
CVE-2025-13033

A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient em

8.6
CVE-2025-63680

Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination wi

7.6
CVE-2025-54346

A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers

7.5
CVE-2025-54345

An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Informati

7.3
CVE-2025-13204

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use

7.3
CVE-2025-13170

A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknow

7.3
CVE-2025-13169

A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerabili

7.5
CVE-2024-21635

Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. Wh

7.5
CVE-2025-9982

A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file a

7.3
CVE-2025-11918

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the

8.1
CVE-2025-8855

Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio

7.2
CVE-2025-64444

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4

7.2
CVE-2025-10686

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possib

7.5
CVE-2025-13161

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo

7.2
CVE-2025-12904

The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA

7.5
CVE-2024-9126

Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a use

7.5
CVE-2024-7017

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potential

7.5
CVE-2025-64530

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions

7.5
CVE-2025-47913

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the cl

8.2
CVE-2025-36236

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a

7.8
CVE-2025-13131

A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\

7.8
CVE-2025-13130

A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra

8.8
CVE-2025-60679

A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210

8.1
CVE-2025-59840

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design

7.8
CVE-2025-46369

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability

7.8
CVE-2025-46367

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Ac

8.8
CVE-2025-63406

An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitra

8.8
CVE-2025-43515

The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauth

7.3
CVE-2025-60698

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a

7.3
CVE-2025-60697

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a

7.3
CVE-2025-13122

A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element i

7.5
CVE-2025-12785

Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started