Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 531/1469
8.4
CVE-2025-0636

EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command cou

7.3
CVE-2025-11662

A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function

7.3
CVE-2025-11661

A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59

7.3
CVE-2025-11660

A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90

7.3
CVE-2025-11659

A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Af

7.3
CVE-2025-11658

A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042

7.3
CVE-2025-11657

A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd

7.3
CVE-2025-11656

A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90

8.1
CVE-2025-36087

IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, an

7.3
CVE-2025-11654

A vulnerability was identified in yousaf530 Inferno Online Clothing Store up to 827dd42bfbe380e8de76fdc67958c24cf1246208

8.8
CVE-2025-11653

A vulnerability was determined in UTT HiPER 2620G up to 3.1.4. Impacted is the function strcpy of the file /goform/fNTP.

8.8
CVE-2025-11652

A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313. This issue affects some unknown processing of the

8.8
CVE-2025-11651

A vulnerability has been found in UTT 进取 518G up to V3v3.2.7-210919-161313. This vulnerability affects the function sub_

7.0
CVE-2025-11649

A vulnerability was found in Tomofun Furbo 360 and Furbo Mini. The affected element is an unknown function of the compon

7.5
CVE-2025-61884 KEV

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions

7.3
CVE-2025-11615

A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. This affects an unknown part of

7.3
CVE-2025-11614

A vulnerability was identified in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknow

7.3
CVE-2025-11608

A security vulnerability has been detected in code-projects E-Banking System 1.0. This affects an unknown function of th

7.3
CVE-2025-11604

A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown process

7.3
CVE-2025-11601

A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an un

7.3
CVE-2025-11599

A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown func

8.8
CVE-2025-8593

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than,

7.3
CVE-2025-11596

A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of t

8.4
CVE-2025-58299

Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may a

7.3
CVE-2025-58298

Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may

7.8
CVE-2025-58287

Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect servi

7.5
CVE-2025-31718

In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of pri

7.5
CVE-2025-31717

In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

8.8
CVE-2025-8093

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati

7.5
CVE-2025-62162

cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.

8.8
CVE-2025-11586

A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgr

7.3
CVE-2025-11585

A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of

7.3
CVE-2025-11584

A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown functio

8.1
CVE-2025-61930

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Requ

7.5
CVE-2025-61921

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a deni

7.5
CVE-2025-61920

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implem

7.5
CVE-2025-61919

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the

8.3
CVE-2025-55903

A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To

7.3
CVE-2025-11583

A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjo

7.3
CVE-2025-11582

A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing o

8.3
CVE-2025-60880

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an a

8.2
CVE-2025-23309

NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of

7.0
CVE-2025-23282

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to esca

7.0
CVE-2025-23280

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex

8.8
CVE-2025-60305

SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a

7.5
CVE-2025-59530

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving

7.3
CVE-2025-60869

Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fie

8.1
CVE-2025-60378

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into in

7.8
CVE-2025-61864

A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially craft

7.8
CVE-2025-61863

An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening sp

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started