Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 646/1469
7.5
CVE-2025-29873

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user

7.5
CVE-2025-29872

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r

7.5
CVE-2025-22490

A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user

8.8
CVE-2025-22486

An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi

8.1
CVE-2025-22482

A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the

8.8
CVE-2025-22481

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the

7.8
CVE-2024-13088

An improper authentication vulnerability has been reported to affect QHora. If an attacker gains local network access, t

8.0
CVE-2025-5806

Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy

7.1
CVE-2025-5791

A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listin

7.3
CVE-2025-5778

A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. Affecte

7.8
CVE-2025-38002

In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uri

7.8
CVE-2025-38001

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding c

7.1
CVE-2025-49453

Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allo

7.1
CVE-2025-49425

Cross-Site Request Forgery (CSRF) vulnerability in Adrian Hanft Konami Easter Egg konami-easter-egg allows Stored XSS.Th

7.6
CVE-2025-49421

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andrei Filonov WP

7.6
CVE-2025-49328

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store

7.6
CVE-2025-49327

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia Short

7.6
CVE-2025-49326

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiP

8.5
CVE-2025-49323

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Boo

7.6
CVE-2025-49315

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PersianScript Pers

7.5
CVE-2025-49313

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2025-49308

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2025-49307

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

8.8
CVE-2025-49288

Missing Authorization vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Authentication Bypass.This is

7.6
CVE-2025-49263

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WCVendors WC Vendo

7.6
CVE-2025-49262

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Ext

7.4
CVE-2025-49237

Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects P

7.8
CVE-2025-38000

In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: Fix qlen accounting bug when using peek i

7.5
CVE-2025-30999

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-30995

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored X

7.6
CVE-2025-30989

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Renzo Tejada Libro

8.2
CVE-2025-28986

Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin epicwin-subscribers allows SQL Injection.

7.1
CVE-2025-28981

Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options wp-mail-options allows Stored XSS.This issue aff

7.1
CVE-2025-28974

Cross-Site Request Forgery (CSRF) vulnerability in mail250 Free WP Mail SMTP free-wp-mail-smtp allows Stored XSS.This is

7.1
CVE-2025-28966

Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive recent-posts-slider-respons

7.1
CVE-2025-28964

Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue

7.1
CVE-2025-28958

Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar bg-orthodox-calendar allows Stor

7.4
CVE-2025-28954

Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp backwp allows Path Traversal.This issue affects Backwp

7.1
CVE-2025-28950

Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author post-author allows Stored XSS.This issue af

7.1
CVE-2025-28948

Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected

7.6
CVE-2025-26590

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nir Complete Googl

7.6
CVE-2023-26003

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in vipul Jariwala WP

7.5
CVE-2023-25995

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-48329

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Real Ti

8.5
CVE-2025-47584

Deserialization of Untrusted Data vulnerability in ThemeGoods Photography.This issue affects Photography: from n/a throu

8.8
CVE-2025-39358

Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Inject

7.3
CVE-2025-5759

A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. This

7.3
CVE-2025-5758

A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This a

7.3
CVE-2025-5756

A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical.

7.3
CVE-2025-5755

A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started