Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 595/1469
7.4
CVE-2025-2824

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to condu

7.5
CVE-2023-32256

A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in mult

7.6
CVE-2025-51504

Microweber CMS 2.0 is vulnerable to Cross Site Scripting (XSS)in the /projects/profile, homepage endpoint via the last n

7.8
CVE-2025-52361

Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allo

7.8
CVE-2025-52327

SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via t

7.2
CVE-2025-44139

Emlog Pro V2.5.7 is vulnerable to Unrestricted Upload of File with Dangerous Type via /emlog/admin/plugin.php?action=upl

7.0
CVE-2025-45767

jose v6.0.10 was discovered to contain weak encryption. NOTE: this is disputed by a third party because the claim of "do

8.8
CVE-2025-41374

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41373

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41372

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41371

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

8.8
CVE-2025-41370

A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The

7.3
CVE-2025-8443

A vulnerability was found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this issue

7.3
CVE-2025-8442

A vulnerability has been found in code-projects Online Medicine Guide 1.0 and classified as critical. Affected by this v

7.3
CVE-2025-8441

A vulnerability, which was classified as critical, was found in code-projects Online Medicine Guide 1.0. Affected is an

7.3
CVE-2025-8439

A vulnerability, which was classified as critical, has been found in code-projects Wazifa System 1.0. This issue affects

7.3
CVE-2025-8438

A vulnerability classified as critical was found in code-projects Wazifa System 1.0. This vulnerability affects unknown

7.3
CVE-2025-8437

A vulnerability classified as critical has been found in code-projects Kitchen Treasure 1.0. This affects an unknown par

7.3
CVE-2025-8436

A vulnerability was found in projectworlds Online Admission System 1.0. It has been rated as critical. Affected by this

7.3
CVE-2025-8435

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been declared as critical. Affected by thi

7.2
CVE-2025-7725

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Str

8.1
CVE-2025-7443

The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript p

7.3
CVE-2025-8434

A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is a

7.3
CVE-2025-8431

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe

7.8
CVE-2025-48071

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the

7.0
CVE-2025-45768

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length i

8.8
CVE-2025-50572

Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into

7.0
CVE-2025-45770

jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths a

7.3
CVE-2025-26064

A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb

7.6
CVE-2025-51503

A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2.0 allows attackers to inject malicious scripts int

7.3
CVE-2025-8409

A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. Affected by this vuln

7.6
CVE-2025-52203

A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1.2.4. The vulnerability res

8.6
CVE-2025-50850

An issue was discovered in CS Cart 4.18.3 allows the vendor login functionality lacks essential security controls such a

7.3
CVE-2025-29556

ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions

7.3
CVE-2025-8408

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. Affected is an unk

8.0
CVE-2025-52289

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileg

8.0
CVE-2025-50849

CS Cart 4.18.3 is vulnerable to Insecure Direct Object Reference (IDOR). The user profile functionality allows enabling

7.3
CVE-2025-8407

A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1.0. This issue af

7.2
CVE-2025-8213

The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficien

7.3
CVE-2025-8378

A vulnerability was found in Campcodes Online Hotel Reservation System 1.0. It has been rated as critical. Affected by t

7.3
CVE-2025-8376

A vulnerability classified as critical has been found in code-projects Vehicle Management 1.0. Affected is an unknown fu

7.2
CVE-2025-41688

A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the

7.5
CVE-2025-2813

An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http servi

7.3
CVE-2025-8375

A vulnerability was found in code-projects Vehicle Management 1.0. It has been rated as critical. This issue affects som

7.3
CVE-2025-8374

A vulnerability was found in code-projects Vehicle Management 1.0. It has been declared as critical. This vulnerability

7.5
CVE-2025-24853

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to

7.3
CVE-2025-8373

A vulnerability was found in code-projects Vehicle Management 1.0. It has been classified as critical. This affects an u

7.3
CVE-2025-8372

A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue i

7.2
CVE-2025-46359

A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator ma

7.3
CVE-2025-8371

A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vu

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started