Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 611/1469
7.3
CVE-2025-7515

A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. This affec

7.3
CVE-2025-7514

A vulnerability was found in code-projects Modern Bag 1.0. It has been rated as critical. Affected by this issue is some

7.3
CVE-2025-7513

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerabil

7.3
CVE-2025-7512

A vulnerability was found in code-projects Modern Bag 1.0. It has been classified as critical. Affected is an unknown fu

7.3
CVE-2025-7510

A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects un

7.3
CVE-2025-7509

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown pa

7.3
CVE-2025-7508

A vulnerability, which was classified as critical, has been found in code-projects Modern Bag 1.0. Affected by this issu

8.8
CVE-2025-7506

A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function

8.8
CVE-2025-7505

A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function frmL7ProtForm of

7.3
CVE-2025-7483

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been rated as critical. This issu

7.5
CVE-2024-41169

The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, in

7.3
CVE-2025-7480

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by t

7.3
CVE-2025-7478

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. Affected is an unknown fun

7.3
CVE-2025-7476

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affec

7.3
CVE-2025-7475

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unk

7.3
CVE-2025-7474

A vulnerability was found in code-projects Job Diary 1.0. It has been rated as critical. Affected by this issue is some

7.3
CVE-2025-7471

A vulnerability was found in code-projects Modern Bag 1.0. It has been declared as critical. Affected by this vulnerabil

7.5
CVE-2020-36848

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Sens

7.3
CVE-2025-7470

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is a

7.3
CVE-2025-7469

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som

7.5
CVE-2025-7504

The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted

8.8
CVE-2025-7468

A vulnerability has been found in Tenda FH1201 1.2.0.14 and classified as critical. This vulnerability affects the funct

7.3
CVE-2025-7467

A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown pa

7.3
CVE-2025-7466

A vulnerability, which was classified as critical, has been found in 1000projects ABC Courier Management 1.0. Affected b

8.8
CVE-2025-6423

The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati

8.8
CVE-2025-7465

A vulnerability classified as critical was found in Tenda FH1201 1.2.0.14. Affected by this vulnerability is the functio

8.8
CVE-2025-7463

A vulnerability was found in Tenda FH1201 1.2.0.14. It has been declared as critical. This vulnerability affects the fun

8.8
CVE-2025-1313

The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in

7.3
CVE-2025-7461

A vulnerability was found in code-projects Modern Bag 1.0 and classified as critical. Affected by this issue is some unk

8.8
CVE-2025-6057

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the han

7.5
CVE-2025-24294

The attack vector is a potential Denial of Service (DoS). The vulnerability is caused by an insufficient check on the le

7.3
CVE-2025-5199

In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker

8.8
CVE-2025-7460

A vulnerability has been found in TOTOLINK T6 4.1.5cu.748_B20211015 and classified as critical. Affected by this vulnera

7.3
CVE-2025-7459

A vulnerability classified as critical was found in code-projects Mobile Shop 1.0. This vulnerability affects unknown co

7.3
CVE-2025-7457

A vulnerability, which was classified as critical, was found in Campcodes Online Movie Theater Seat Reservation System 1

7.3
CVE-2025-7456

A vulnerability, which was classified as critical, has been found in Campcodes Online Movie Theater Seat Reservation Sys

7.3
CVE-2025-7455

A vulnerability classified as critical was found in Campcodes Online Movie Theater Seat Reservation System 1.0. Affected

7.3
CVE-2025-7454

A vulnerability classified as critical has been found in Campcodes Online Movie Theater Seat Reservation System 1.0. Aff

8.1
CVE-2025-30403

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This is

8.3
CVE-2013-3307

Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj

8.2
CVE-2025-53641

Postiz is an AI social media scheduling tool. From 1.45.1 to 1.62.3, the Postiz frontend application allows an attacker

8.1
CVE-2025-30402

A heap-buffer-overflow vulnerability in the loading of ExecuTorch methods can cause the runtime to crash and potentially

8.2
CVE-2025-7029

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register,

7.8
CVE-2025-7028

A vulnerability in the Software SMI handler (SwSmiInputValue 0x20) allows a local attacker to supply a crafted pointer (

8.2
CVE-2025-7027

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control both the read and

8.2
CVE-2025-7026

A vulnerability in the Software SMI handler (SwSmiInputValue 0xB2) allows a local attacker to control the RBX register,

7.2
CVE-2025-52983

A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a

7.5
CVE-2025-52981

An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow processing daemon (flowd) of Juniper N

7.5
CVE-2025-52980

A Use of Incorrect Byte Ordering vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS on

7.8
CVE-2025-52954

A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started