Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 663/1469
7.3
CVE-2025-4724

A vulnerability, which was classified as critical, has been found in itsourcecode Placement Management System 1.0. Affec

7.3
CVE-2025-4723

A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne

7.3
CVE-2025-4722

A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un

7.5
CVE-2025-47287

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser enc

7.3
CVE-2025-4721

A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff

7.3
CVE-2025-4719

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue

7.3
CVE-2025-4718

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-4717

A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affect

7.3
CVE-2025-4716

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this i

7.3
CVE-2025-4715

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by thi

8.3
CVE-2025-47785

Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the

7.8
CVE-2025-47161

Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.

7.2
CVE-2024-9831

The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme

7.5
CVE-2024-8700

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent

7.2
CVE-2024-8699

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users

8.1
CVE-2024-6719

The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co

7.2
CVE-2024-6486

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec

7.5
CVE-2024-12812

The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before

7.2
CVE-2024-12735

The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL

7.2
CVE-2024-11372

The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL stat

7.2
CVE-2024-11269

The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statem

8.8
CVE-2024-11267

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta

8.8
CVE-2024-0852

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting i

7.1
CVE-2024-0249

The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it

7.5
CVE-2023-7239

The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id paramete

7.3
CVE-2023-7231

The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to del

7.1
CVE-2023-7197

The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisa

7.1
CVE-2023-7174

The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisa

7.3
CVE-2023-5934

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when

7.3
CVE-2025-4714

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is a

7.3
CVE-2025-4713

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som

7.3
CVE-2025-4712

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit

7.1
CVE-2025-32922

Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This iss

8.1
CVE-2025-30475

Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthe

7.5
CVE-2025-26481

Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A

7.3
CVE-2025-4711

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects a

7.3
CVE-2025-4710

A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected

7.3
CVE-2025-4709

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerabi

7.3
CVE-2025-4708

A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknow

7.3
CVE-2025-4707

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects

7.3
CVE-2025-4706

A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnera

7.8
CVE-2025-30421

There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when

7.8
CVE-2025-30420

There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolE

7.8
CVE-2025-30419

There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the Symb

7.8
CVE-2025-30418

There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in N

7.8
CVE-2025-30417

There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the Symbol

7.3
CVE-2025-4705

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This

7.3
CVE-2025-4704

A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by t

7.3
CVE-2025-4703

A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected

7.5
CVE-2025-48050

In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the curren

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started