Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 547/1469
8.8
CVE-2025-10380

The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template I

7.3
CVE-2025-10834

A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. This affects an unknown function of the file

7.3
CVE-2025-10833

A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown funct

7.3
CVE-2025-10832

A vulnerability was found in SourceCodester Pet Grooming Management Software 1.0. The affected element is an unknown fun

7.3
CVE-2025-10831

A vulnerability has been found in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of

7.3
CVE-2025-10830

A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. This issue affects some unknown processing o

7.3
CVE-2025-10829

A vulnerability was detected in Campcodes Computer Sales and Inventory System 1.0. This vulnerability affects unknown co

7.3
CVE-2025-10817

A weakness has been identified in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown co

7.3
CVE-2025-10816

A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/Too

8.8
CVE-2025-10815

A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this issue is the function strcpy of the fil

7.5
CVE-2025-59527

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side

7.3
CVE-2025-10813

A vulnerability was found in code-projects Hostel Management System 1.0. Affected is an unknown function of the file /ju

7.3
CVE-2025-10812

A vulnerability has been found in code-projects Hostel Management System 1.0. This impacts an unknown function of the fi

7.8
CVE-2025-8892

A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili

7.5
CVE-2025-59588

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

8.8
CVE-2025-59572

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Cross Site Request Fo

7.6
CVE-2025-59570

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Min

8.2
CVE-2025-59430

Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect. Prior to version 3.3.2, the lack of sanitiz

7.5
CVE-2025-58973

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-58956

Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System wp-attractive-donations-system-

7.1
CVE-2025-58690

Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect doliconnect allows Stored XSS.This issue affect

7.1
CVE-2025-58688

Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support the-casengo-chat-widget allows Stor

7.1
CVE-2025-58687

Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin current-age allows Stored XSS.This is

8.5
CVE-2025-58686

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect

7.1
CVE-2025-58677

Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews shrinktheweb-website

7.1
CVE-2025-58676

Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER horizontal-slider allows Stored XSS.T

7.1
CVE-2025-58671

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auc

7.1
CVE-2025-58670

Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection wp-content-protection allow

7.2
CVE-2025-58662

Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injectio

7.1
CVE-2025-58657

Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid grid allows Stored XSS.This issue affects Grid: from

7.1
CVE-2025-58270

Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cros

7.1
CVE-2025-58268

Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator wpmk-pdf-generator allows Stored XSS.This iss

7.1
CVE-2025-58267

Cross-Site Request Forgery (CSRF) vulnerability in Aftabul Islam Stock Message stock-message allows Stored XSS.This issu

7.1
CVE-2025-58262

Cross-Site Request Forgery (CSRF) vulnerability in WPDirectoryKit Sweet Energy Efficiency sweet-energy-efficiency allows

7.1
CVE-2025-58261

Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-htt

7.1
CVE-2025-58259

Cross-Site Request Forgery (CSRF) vulnerability in scriptsbundle Nokri nokri allows Cross Site Request Forgery.This issu

8.8
CVE-2025-58250

Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo fingo allows Authentication Bypass.This issue affect

8.8
CVE-2025-58244

Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo constructo allows Object Injection.This issue affects

8.8
CVE-2025-58013

Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL couponxxl allows Privilege Escalation.This issue affe

7.1
CVE-2025-57977

Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress flexible-inv

7.1
CVE-2025-57968

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestau

7.5
CVE-2025-57925

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.2
CVE-2025-57919

Deserialization of Untrusted Data vulnerability in ConveyThis ConveyThis conveythis-translate allows Object Injection.Th

7.1
CVE-2025-57918

Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude linkedinclude allows Stored XSS.This issue affec

8.8
CVE-2025-57685

The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B

8.5
CVE-2025-53468

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in [email protected]

7.2
CVE-2025-53465

Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector sheetlink allows Object Injection.This

7.5
CVE-2025-53450

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.3
CVE-2025-10811

A flaw has been found in code-projects Hostel Management System 1.0. This affects an unknown function of the file /justi

7.3
CVE-2025-10810

A vulnerability was detected in Campcodes Online Learning Management System 1.0. The impacted element is an unknown func

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started