Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 625/1469
7.3
CVE-2025-6901

A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affect

7.8
CVE-2025-53416

Delta Electronics DTN Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

7.5
CVE-2024-8419

The endpoint hosts a script that allows an unauthorized remote attacker to put the system in a fail-safe state over the

7.8
CVE-2025-53415

Delta Electronics DTM Soft Project File Parsing Deserialization of Untrusted Data Remote Code Execution

7.5
CVE-2025-40732

user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent

7.8
CVE-2025-38090

In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap ove

7.1
CVE-2025-38088

In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue i

7.8
CVE-2025-38087

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix use-after-free in taprio_dev_notifie

7.3
CVE-2025-6891

A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an u

7.3
CVE-2025-6889

A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerabil

7.3
CVE-2025-6888

A vulnerability was found in PHPGurukul Teachers Record Management System 2.1. It has been classified as critical. This

8.8
CVE-2025-6887

A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown fu

8.8
CVE-2025-6886

A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an

7.3
CVE-2025-6885

A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2.1. Affect

8.8
CVE-2025-6882

A vulnerability classified as critical has been found in D-Link DIR-513 1.0. This affects an unknown part of the file /g

8.8
CVE-2025-6881

A vulnerability was found in D-Link DI-8100 16.07.21. It has been rated as critical. Affected by this issue is some unkn

8.8
CVE-2025-46014

Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named p

7.3
CVE-2025-6871

A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unkn

7.5
CVE-2025-24289

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin

7.3
CVE-2025-6863

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affec

7.3
CVE-2025-5878

A vulnerability was found in ESAPI esapi-java-legacy and classified as problematic. This issue affects the interface Enc

7.3
CVE-2025-6846

A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of

7.3
CVE-2025-6845

A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is so

7.3
CVE-2025-6844

A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerab

7.3
CVE-2025-6843

A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an

7.3
CVE-2025-6840

A vulnerability, which was classified as critical, was found in code-projects Product Inventory System 1.0. This affects

7.3
CVE-2025-6836

A vulnerability classified as critical has been found in code-projects Library System 1.0. Affected is an unknown functi

7.3
CVE-2025-6835

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some un

7.3
CVE-2025-6834

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulne

7.3
CVE-2025-6828

A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnera

7.3
CVE-2025-6827

A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affe

7.3
CVE-2025-6826

A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affect

8.8
CVE-2025-6825

A vulnerability classified as critical was found in TOTOLINK A702R up to 4.0.0-B20230721.1521. Affected by this vulnerab

8.8
CVE-2025-6824

A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown

7.3
CVE-2025-6823

A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue af

7.3
CVE-2025-6822

A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulne

7.3
CVE-2025-6821

A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This aff

7.3
CVE-2025-6820

A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-6819

A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by

8.0
CVE-2023-28910

A specific flaw exists within the Bluetooth stack of the MIB3 infotainment system. The issue results from the disabled a

8.0
CVE-2023-28909

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation

7.8
CVE-2023-28906

A command injection in the networking service of the MIB3 infotainment allows an attacker already presenting in the syst

8.0
CVE-2023-28905

A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitr

7.5
CVE-2025-1991

IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an in

7.8
CVE-2025-38085

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race

7.8
CVE-2025-38084

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, n

8.8
CVE-2025-6755

The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path

8.8
CVE-2025-6381

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including

8.8
CVE-2025-6379

The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu

8.1
CVE-2025-53098

Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stor

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started