Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 631/1469
7.3
CVE-2025-6408

A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. This vulne

7.3
CVE-2025-6407

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. This af

7.3
CVE-2025-6406

A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Af

7.3
CVE-2025-6405

A vulnerability classified as critical was found in Campcodes Online Teacher Record Management System 1.0. Affected by t

7.5
CVE-2025-3221

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a remote attacker to cause a denial of service d

7.3
CVE-2025-6404

A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected

7.3
CVE-2025-6403

A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue aff

8.8
CVE-2025-6402

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability aff

8.8
CVE-2025-6400

A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101 and classified as critical. Affected by this issue is s

7.1
CVE-2025-5034

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in

8.8
CVE-2025-6399

A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknow

8.6
CVE-2025-52488

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In version

7.5
CVE-2025-52487

DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In version

7.3
CVE-2025-6394

A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical.

8.8
CVE-2025-6393

A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0

8.8
CVE-2025-6374

A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. This issue affects the function formSet

7.8
CVE-2025-6218 KEV

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exe

8.8
CVE-2025-5820

Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability. This vulnerability allows network-adjacent a

7.5
CVE-2025-5479

Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil

8.8
CVE-2025-5478

Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows n

7.5
CVE-2025-5477

Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil

8.8
CVE-2025-5476

Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adja

7.5
CVE-2025-5475

Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow

8.8
CVE-2025-6373

A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. This vulnerability affects the fun

8.8
CVE-2025-6372

A vulnerability, which was classified as critical, was found in D-Link DIR-619L 2.06B01. This affects the function formS

8.8
CVE-2025-6371

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L 2.06B01. Affected by this issue is

8.8
CVE-2025-6370

A vulnerability classified as critical was found in D-Link DIR-619L 2.06B01. Affected by this vulnerability is the funct

8.8
CVE-2025-6369

A vulnerability classified as critical has been found in D-Link DIR-619L 2.06B01. Affected is the function formdumpeasys

8.8
CVE-2025-6368

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been rated as critical. This issue affects the function for

8.8
CVE-2025-6367

A vulnerability was found in D-Link DIR-619L 2.06B01. It has been declared as critical. This vulnerability affects unkno

7.3
CVE-2025-6364

A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by

7.3
CVE-2025-6363

A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected

7.3
CVE-2025-6362

A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. Thi

7.3
CVE-2025-6361

A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability a

7.3
CVE-2025-6360

A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an

7.3
CVE-2025-6359

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. Affected by

8.8
CVE-2025-34029

An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscm

8.8
CVE-2025-34024

An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp for

8.1
CVE-2024-4994

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting fr

7.3
CVE-2025-6358

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. Affected

7.3
CVE-2025-6357

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. Affecte

7.3
CVE-2025-6356

A vulnerability was found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. This issue affec

8.5
CVE-2025-5121

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A

8.7
CVE-2025-2443

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass

7.3
CVE-2025-6355

A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vu

7.3
CVE-2025-6354

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by th

7.5
CVE-2025-45331

brplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its da

7.5
CVE-2025-44203

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is com

8.8
CVE-2025-52825

Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege

8.5
CVE-2025-52822

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP R

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started