Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 533/1469
8.8
CVE-2025-10240

A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a mali

7.2
CVE-2025-10239

In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privilege

7.7
CVE-2025-11340

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certa

7.5
CVE-2025-10004

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to

7.8
CVE-2025-39958

In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was

7.1
CVE-2025-39957

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Curr

7.8
CVE-2025-39956

In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error Whe

7.8
CVE-2025-39955

In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconne

7.5
CVE-2025-10862

The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr

8.8
CVE-2025-6038

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable

7.8
CVE-2025-47355

Memory corruption while invoking remote procedure IOCTL calls.

7.8
CVE-2025-47354

Memory corruption while allocating buffers in DSP service.

7.8
CVE-2025-47351

Memory corruption while processing user buffers.

7.8
CVE-2025-47349

Memory corruption while processing an escape call.

7.8
CVE-2025-47347

Memory corruption while processing control commands in the virtual memory management interface.

7.1
CVE-2025-47342

Transient DOS may occur when multi-profile concurrency arises with QHS enabled.

7.8
CVE-2025-47341

memory corruption while processing an image encoding completion event.

7.8
CVE-2025-47340

Memory corruption while processing IOCTL call to get the mapping.

7.8
CVE-2025-47338

Memory corruption while processing escape commands from userspace.

8.8
CVE-2025-27060

Memory corruption while performing SCM call with malformed inputs.

8.8
CVE-2025-27059

Memory corruption while performing SCM call.

7.8
CVE-2025-27054

Memory corruption while processing a malformed license file during reboot.

7.8
CVE-2025-27053

Memory corruption during PlayReady APP usecase while processing TA commands.

7.8
CVE-2025-27048

Memory corruption while processing camera platform driver IOCTL calls.

7.3
CVE-2025-11529

A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/

8.8
CVE-2025-11528

A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQo

8.8
CVE-2025-11527

A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform

8.8
CVE-2025-11526

A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/Wifi

8.8
CVE-2025-11525

A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg.

8.8
CVE-2025-11524

A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCf

7.2
CVE-2025-10496

The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in

7.3
CVE-2025-11513

A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/

7.3
CVE-2025-11507

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown fu

7.3
CVE-2025-11506

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unkno

7.3
CVE-2025-11505

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of th

8.8
CVE-2025-60311

ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php pag

7.3
CVE-2025-11503

A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown proce

7.2
CVE-2025-61524

An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and bef

8.8
CVE-2025-57457

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject

7.3
CVE-2025-11488

A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Execu

7.4
CVE-2025-9970

Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.

8.0
CVE-2025-53967

Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system

7.3
CVE-2025-11480

A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown funct

7.3
CVE-2025-11479

A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the

7.3
CVE-2025-11477

A security flaw has been discovered in SourceCodester Wedding Reservation Management System 1.0. This vulnerability affe

7.3
CVE-2025-11476

A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the fi

7.3
CVE-2025-11475

A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u

7.3
CVE-2025-11473

A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function

7.3
CVE-2025-11472

A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the f

7.3
CVE-2025-11471

A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function o

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started