Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 606/1469
7.3
CVE-2025-7897

A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1.2.6 and classified as critical. Affected by this issue

8.6
CVE-2025-46385

CWE-918 Server-Side Request Forgery (SSRF)

8.8
CVE-2025-46384

CWE-434 Unrestricted Upload of File with Dangerous Type

7.3
CVE-2025-7886

A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f

7.8
CVE-2025-7883

A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown f

7.3
CVE-2025-7875

A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6.4.2. This affects an unknown part

7.3
CVE-2025-7862

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnera

7.3
CVE-2025-7861

A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1.0. Affected is an

7.3
CVE-2025-7860

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issu

7.3
CVE-2025-7859

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects

8.8
CVE-2025-7855

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function

8.8
CVE-2025-7854

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function fromVirtualSer of

8.8
CVE-2025-7853

A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function fromSet

7.3
CVE-2025-7838

A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1.0 and classified as critical.

8.8
CVE-2025-7837

A vulnerability was found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this issue is the

7.5
CVE-2025-54313 KEV

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Inst

7.3
CVE-2025-7833

A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1.0. This issu

7.3
CVE-2025-7832

A vulnerability classified as critical was found in code-projects Church Donation System 1.0. This vulnerability affects

7.3
CVE-2025-7831

A vulnerability classified as critical has been found in code-projects Church Donation System 1.0. This affects an unkno

7.3
CVE-2025-7830

A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i

7.3
CVE-2025-7829

A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi

7.3
CVE-2025-7824

A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing

7.3
CVE-2025-7823

A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code

8.8
CVE-2015-10139

The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import

7.5
CVE-2015-10136

The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' p

7.5
CVE-2015-10134

The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10

7.2
CVE-2015-10133

The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi

7.8
CVE-2025-38350

In the Linux kernel, the following vulnerability has been resolved: net/sched: Always pass notifications when child cla

7.5
CVE-2025-27210

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CO

7.5
CVE-2025-27209

The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation r

7.3
CVE-2025-7814

A vulnerability classified as critical was found in code-projects Food Ordering Review System 1.0. This vulnerability af

8.8
CVE-2025-7807

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. This issue affects the functio

8.8
CVE-2025-7806

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. This vulnerability affects the function fromSaf

8.8
CVE-2025-7805

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromPptpUserSett

7.5
CVE-2025-50708

An issue in Perplexity AI GPT-4 v.2.51.0 allows a remote attacker to obtain sensitive information via the token componen

7.3
CVE-2025-7801

A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unkn

7.1
CVE-2025-52169

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS

8.8
CVE-2025-50585

StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.

8.8
CVE-2025-7796

A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpU

8.8
CVE-2025-7795

A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the

8.2
CVE-2025-52164

Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.

8.8
CVE-2025-7794

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function

8.8
CVE-2025-7793

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrar

8.8
CVE-2025-7792

A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSaf

8.7
CVE-2025-53762

Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a networ

8.8
CVE-2025-7790

A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. This affects an unknown part

8.8
CVE-2025-54079

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection

8.3
CVE-2025-54075

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.1

7.5
CVE-2025-54073

mcp-package-docs is an MCP (Model Context Protocol) server that provides LLMs with efficient access to package documenta

7.0
CVE-2025-53945

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prio

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started