Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 562/1469
7.3
CVE-2025-10114

A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file

8.8
CVE-2025-58757

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the

8.8
CVE-2025-58756

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in

8.8
CVE-2025-58755

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta

7.3
CVE-2025-10113

A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un

7.3
CVE-2025-10112

A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk

8.2
CVE-2025-58454

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1

8.2
CVE-2025-58453

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1

7.3
CVE-2025-10111

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a

7.3
CVE-2025-10109

A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin

7.2
CVE-2025-57817

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endp

7.5
CVE-2025-57816

Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-bas

7.3
CVE-2025-10108

A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the

7.5
CVE-2025-52288

Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Ma

8.8
CVE-2025-52389

An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke

7.3
CVE-2025-10104

A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func

8.8
CVE-2025-9112

The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do

8.4
CVE-2025-55849

WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee

7.3
CVE-2025-10103

A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the

7.3
CVE-2025-10102

A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o

8.8
CVE-2025-56265

An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac

7.3
CVE-2025-10100

A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t

7.4
CVE-2025-59033

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries

7.3
CVE-2025-56630

FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Colum

8.1
CVE-2025-55998

A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacke

7.5
CVE-2025-40930

JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing craft

7.5
CVE-2025-40928

JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl

7.4
CVE-2022-50238

The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended dr

8.8
CVE-2025-36855

A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. P

8.1
CVE-2025-36854

A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream whi

7.5
CVE-2025-36853

A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122:

7.3
CVE-2025-10092

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectman

7.3
CVE-2025-10091

A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.proje

7.3
CVE-2025-10090

A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.dep

7.4
CVE-2025-41708

Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke

8.8
CVE-2025-41682

An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufactu

7.5
CVE-2025-41664

A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates

8.6
CVE-2025-8085

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoi

7.3
CVE-2025-10082

A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file

7.3
CVE-2025-10079

A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the fil

7.3
CVE-2025-10078

A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /a

7.3
CVE-2025-10077

A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function

7.3
CVE-2025-10076

A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file

7.8
CVE-2025-39732

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_

7.8
CVE-2025-39730

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_de

7.8
CVE-2025-39727

In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix potential buffer overflow in setup_cl

7.3
CVE-2025-10068

A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/a

7.3
CVE-2025-10062

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part o

7.5
CVE-2025-58445

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions o

7.5
CVE-2025-58446

xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer intr

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started