Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 599/1469
8.8
CVE-2025-8242

A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affec

7.3
CVE-2025-8241

A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. This af

7.3
CVE-2025-8240

A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by

7.3
CVE-2025-8239

A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerabili

7.3
CVE-2025-8238

A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown

7.3
CVE-2025-8237

A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s

7.3
CVE-2025-8236

A vulnerability was found in code-projects Online Ordering System 1.0. It has been declared as critical. This vulnerabil

7.3
CVE-2025-8235

A vulnerability was found in code-projects Online Ordering System 1.0. It has been classified as critical. This affects

7.3
CVE-2025-8234

A vulnerability was found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this issue

7.3
CVE-2025-8233

A vulnerability has been found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-8232

A vulnerability, which was classified as critical, was found in code-projects Online Ordering System 1.0. Affected is an

7.3
CVE-2025-8220

A vulnerability has been found in Engeman Web up to 12.0.0.2. The affected element is an unknown function of the file /L

7.2
CVE-2025-54597

LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.

7.3
CVE-2025-8185

A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affect

8.8
CVE-2025-8184

A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formS

7.5
CVE-2025-6991

The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via t

8.1
CVE-2025-6989

The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in t

7.2
CVE-2025-8181

A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unkno

8.8
CVE-2025-8180

A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the f

7.5
CVE-2025-8198

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in

7.3
CVE-2025-8179

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affec

8.8
CVE-2025-8178

A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the

8.3
CVE-2025-54378

HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcm

8.8
CVE-2025-54366

FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1

7.5
CVE-2024-13507

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to

7.3
CVE-2025-8173

A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected b

8.8
CVE-2025-8170

A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the fu

8.8
CVE-2025-8169

A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPca

8.8
CVE-2025-8168

A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function

8.8
CVE-2025-46198

Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code

7.3
CVE-2025-8166

A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a

8.2
CVE-2025-52454

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector mod

8.2
CVE-2025-52453

Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source module

8.5
CVE-2025-52452

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve

8.5
CVE-2025-52449

Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible

8.1
CVE-2025-52448

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-

8.1
CVE-2025-52447

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initi

8.0
CVE-2025-52446

Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc a

8.3
CVE-2025-36727

Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: befo

7.2
CVE-2023-53155

goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.

8.8
CVE-2025-45466

Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded

7.8
CVE-2025-38466

In the Linux kernel, the following vulnerability has been resolved: perf: Revert to requiring CAP_SYS_ADMIN for uprobes

7.8
CVE-2025-38464

In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_conn_close(). syz

7.8
CVE-2025-38463

In the Linux kernel, the following vulnerability has been resolved: tcp: Correct signedness in skb remaining space calc

7.0
CVE-2025-38461

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment

7.0
CVE-2025-38460

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix potential null-ptr-deref in to_atmar

7.8
CVE-2025-38459

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push

7.8
CVE-2025-38456

In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Fix potential memory corruption in

7.8
CVE-2025-38455

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Reject SEV{-ES} intra host migration if v

7.8
CVE-2025-38453

In the Linux kernel, the following vulnerability has been resolved: io_uring/msg_ring: ensure io_kiocb freeing is defer

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started