Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 662/1469
7.1
CVE-2025-48112

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot ht

7.5
CVE-2025-47693

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.6
CVE-2025-47567

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Video

7.1
CVE-2025-39537

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Bet

7.5
CVE-2025-39507

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2025-39492

Path Traversal vulnerability in WHMPress WHMpress allows Relative Path Traversal. This issue affects WHMpress: from 6.2

8.1
CVE-2025-39491

Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through r

8.8
CVE-2025-32310

Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quick

8.5
CVE-2025-32307

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Chame

8.5
CVE-2025-32306

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Radio

8.5
CVE-2025-32301

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Count

8.5
CVE-2025-32290

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick

8.5
CVE-2025-32287

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Respo

8.5
CVE-2025-31928

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Multi

8.5
CVE-2025-31926

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Stick

7.1
CVE-2025-31922

Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Sto

8.5
CVE-2025-31641

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup UberS

8.5
CVE-2025-31640

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Magic

8.5
CVE-2025-31637

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup SHOUT

7.3
CVE-2025-4785

A vulnerability was found in PHPGurukul Daily Expense Tracker System 1.1. It has been rated as critical. Affected by thi

7.5
CVE-2025-4600

A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling

7.3
CVE-2025-4773

A vulnerability was found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this issu

7.8
CVE-2025-37890

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class w

8.6
CVE-2025-2305

A Path traversal vulnerability in the file download functionality was identified. This vulnerability allows unauthentica

7.3
CVE-2025-4772

A vulnerability has been found in PHPGurukul Online Course Registration 3.1 and classified as critical. Affected by this

7.3
CVE-2025-4771

A vulnerability, which was classified as critical, was found in PHPGurukul Online Course Registration 3.1. Affected is a

7.0
CVE-2025-4769

A vulnerability classified as critical was found in CBEWIN Anytxt Searcher 1.3.1128.0. This vulnerability affects unknow

7.3
CVE-2025-4766

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vu

7.3
CVE-2025-4765

A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been classified as critical. Affected is an un

7.5
CVE-2025-1975

A vulnerability in the Ollama server version 0.5.11 allows a malicious user to cause a Denial of Service (DoS) attack by

7.3
CVE-2025-4761

A vulnerability has been found in PHPGurukul Complaint Management System 2.0 and classified as critical. This vulnerabil

7.3
CVE-2025-4758

A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an

7.3
CVE-2025-4757

A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. It has been rated as critical. This issue

7.5
CVE-2024-53827

Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially cra

7.3
CVE-2025-4755

A vulnerability was found in D-Link DI-7003GV2 24.04.18D1 R(68125). It has been classified as critical. This affects the

8.3
CVE-2025-4759

Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via

7.5
CVE-2025-4749

A vulnerability classified as critical was found in D-Link DI-7003GV2 24.04.18D1 R(68125). This vulnerability affects th

7.3
CVE-2025-4746

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit

7.3
CVE-2025-4741

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects

7.3
CVE-2025-4739

A vulnerability was found in projectworlds Hospital Database Management System 1.0. It has been classified as critical.

7.3
CVE-2025-4736

A vulnerability was found in PHPGurukul Daily Expense Tracker 1.1 and classified as critical. Affected by this issue is

7.3
CVE-2025-4734

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. Affected is an

8.8
CVE-2025-4733

A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. T

8.8
CVE-2025-4732

A vulnerability classified as critical was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability

8.2
CVE-2025-47809

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reb

8.8
CVE-2025-4731

A vulnerability classified as critical has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This affects

8.8
CVE-2025-4730

A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected b

7.3
CVE-2025-4728

A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is

7.3
CVE-2025-4726

A vulnerability has been found in itsourcecode Placement Management System 1.0 and classified as critical. This vulnerab

7.3
CVE-2025-4725

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. This affec

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started