Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 624/1469
8.8
CVE-2025-5014

The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff

7.5
CVE-2025-4381

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via

8.1
CVE-2025-4380

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus

8.4
CVE-2025-36630

In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit

7.4
CVE-2025-49741

No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a

7.1
CVE-2025-48379

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a

7.5
CVE-2025-53107

@cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is

8.8
CVE-2025-45081

Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.

7.5
CVE-2025-34081

The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may cont

8.2
CVE-2025-6297

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a

7.3
CVE-2025-6963

A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit

7.3
CVE-2025-6962

A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a

7.3
CVE-2025-6961

A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected

7.3
CVE-2025-6960

A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi

7.3
CVE-2025-6959

A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow

7.3
CVE-2025-6958

A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects

7.3
CVE-2025-6957

A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil

7.5
CVE-2025-53099

Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a

7.5
CVE-2025-37098

A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

7.3
CVE-2025-6956

A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects

7.3
CVE-2025-6955

A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue

7.3
CVE-2025-6954

A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this

8.8
CVE-2025-6953

A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an un

7.5
CVE-2025-37097

A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service

7.4
CVE-2025-49480

Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lz

7.4
CVE-2025-49492

Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun.  This vulnerability is associated with pr

8.8
CVE-2025-6940

A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability

8.8
CVE-2025-6939

A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown f

7.3
CVE-2025-6938

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue a

7.8
CVE-2024-46992

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro

7.3
CVE-2025-6937

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vuln

7.3
CVE-2025-6936

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This af

7.3
CVE-2025-6935

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue

8.1
CVE-2025-6554 KEV

Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v

8.8
CVE-2025-49521

A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec valu

8.8
CVE-2025-49520

A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to t

8.0
CVE-2025-52995

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ

8.8
CVE-2025-36593

Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerab

7.3
CVE-2025-6917

A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability

8.8
CVE-2025-52898

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request cou

8.8
CVE-2025-6916

A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the func

7.5
CVE-2025-52895

Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved

7.0
CVE-2025-45143

string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

7.5
CVE-2024-53621

A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow

7.3
CVE-2025-6907

A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unkn

7.3
CVE-2025-6906

A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown pa

7.3
CVE-2025-6905

A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue aff

7.3
CVE-2025-6904

A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue

7.3
CVE-2025-6903

A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vul

7.3
CVE-2025-6902

A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started