Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 653/1469
7.3
CVE-2025-5224

A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. Affected is an

7.3
CVE-2025-5221

A vulnerability was found in FreeFloat FTP Server 1.0.0. It has been classified as critical. This affects an unknown par

7.3
CVE-2025-5220

A vulnerability was found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this issue is some unkno

7.3
CVE-2025-5219

A vulnerability has been found in FreeFloat FTP Server 1.0.0 and classified as critical. Affected by this vulnerability

7.3
CVE-2025-5218

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.0. Affected is an unknown funct

7.3
CVE-2025-5217

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0.0. This issue affects some

7.3
CVE-2025-5216

A vulnerability classified as critical was found in PHPGurukul Student Record System 3.20. This vulnerability affects un

8.8
CVE-2025-5215

A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEve

7.3
CVE-2025-5214

A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected b

7.3
CVE-2025-5213

A vulnerability was found in projectworlds Responsive E-Learning System 1.0. It has been declared as critical. Affected

7.3
CVE-2025-5212

A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been classified as critical. Affec

7.3
CVE-2025-5211

A vulnerability was found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This issue aff

7.3
CVE-2025-5210

A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. This vuln

7.3
CVE-2025-5208

A vulnerability, which was classified as critical, was found in SourceCodester Online Hospital Management System 1.0. Th

7.3
CVE-2025-5205

A vulnerability classified as critical has been found in 1000 Projects Daily College Class Work Report Book 1.0. Affecte

7.8
CVE-2025-23395

Screen 5.0.0 when it runs with setuid-root privileges does not drop privileges while operating on a user supplied path.

7.0
CVE-2025-5180

A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue

7.5
CVE-2025-41655

An unauthenticated remote attacker can access a URL which causes the device to reboot.

8.2
CVE-2025-41654

An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of r

7.3
CVE-2025-5176

A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This

7.3
CVE-2025-5172

A vulnerability, which was classified as critical, was found in Econtrata up to 20250516. Affected is an unknown functio

8.8
CVE-2025-5156

A vulnerability was found in H3C GR-5400AX up to 100R008 and classified as critical. Affected by this issue is the funct

7.0
CVE-2025-5129

A vulnerability has been found in Sangfor 零信任访问控制系统 aTrust 2.3.10.60 and classified as critical. Affected by this vulner

7.3
CVE-2025-5128

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected

8.8
CVE-2025-5126

A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the

8.1
CVE-2025-5124

A vulnerability classified as critical has been found in Sony SNC-M1, SNC-M3, SNC-RZ25N, SNC-RZ30N, SNC-DS10, SNC-CS3N a

8.1
CVE-2025-4336

The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing

7.3
CVE-2025-5119

A vulnerability has been found in Emlog Pro 2.5.11 and classified as critical. This vulnerability affects unknown code o

7.6
CVE-2025-43860

OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-

7.6
CVE-2025-32794

OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-

7.8
CVE-2025-24917

In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could

7.0
CVE-2025-24916

When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions pr

7.5
CVE-2022-31812

A vulnerability has been identified in SiPass integrated (All versions < V2.95.3.18). Affected server applications conta

7.5
CVE-2018-25110

Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophi

7.3
CVE-2025-5112

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o

7.3
CVE-2025-5111

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is

7.3
CVE-2025-5110

A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno

7.3
CVE-2025-5109

A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th

8.1
CVE-2025-48292

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-48286

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catkin ReDi Restau

7.5
CVE-2025-48273

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Porta

7.1
CVE-2025-48245

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal Quick C

7.1
CVE-2025-48241

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Soft8Soft LLC Verg

8.8
CVE-2025-47690

Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allow

7.1
CVE-2025-47680

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup

7.1
CVE-2025-47678

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit Funn

7.1
CVE-2025-47673

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc

8.1
CVE-2025-47672

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.6
CVE-2025-47671

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LETSCMS MLM Softwa

8.1
CVE-2025-47670

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started