Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 684/1469
7.5
CVE-2025-2092

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49

7.6
CVE-2025-46252

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Messag

7.1
CVE-2025-46251

Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forg

7.6
CVE-2025-46242

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu

8.2
CVE-2025-46241

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar

7.5
CVE-2025-26413

Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a

8.1
CVE-2025-2594

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when

7.1
CVE-2024-13569

The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i

8.8
CVE-2025-3616

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m

7.1
CVE-2024-46899

Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia

7.8
CVE-2025-1731

An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware

8.0
CVE-2025-3854

A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function E

7.3
CVE-2025-3847

A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part

7.3
CVE-2025-3846

A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is

7.3
CVE-2025-3845

A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner

8.0
CVE-2025-32956

ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ

8.1
CVE-2025-27086

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

8.8
CVE-2024-57394

The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore

7.5
CVE-2025-23174

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

8.1
CVE-2025-43922

The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca

7.5
CVE-2025-3857

When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check t

8.6
CVE-2025-43971

An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value

7.3
CVE-2025-3829

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is

7.3
CVE-2025-3828

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s

7.3
CVE-2025-3827

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil

8.8
CVE-2025-3820

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this

7.3
CVE-2025-3819

A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by thi

8.2
CVE-2025-43917

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst

8.8
CVE-2025-3803

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue af

8.8
CVE-2025-3802

A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulne

7.3
CVE-2025-3800

A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown funct

7.3
CVE-2025-3799

A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app

8.8
CVE-2025-3404

The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat

7.2
CVE-2025-3809

The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log i

7.5
CVE-2025-2111

The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a

7.5
CVE-2024-13926

The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain

7.5
CVE-2025-3103

The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu

7.5
CVE-2025-2010

The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injecti

8.7
CVE-2025-32953

z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubunt

7.8
CVE-2025-24914

When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu

8.8
CVE-2025-28237

An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges

7.5
CVE-2025-28235

An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 a

7.8
CVE-2025-1697

A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products

7.5
CVE-2025-28059

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system re

7.5
CVE-2025-32442

Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, app

7.1
CVE-2025-31118

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum q

7.3
CVE-2025-30357

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a ma

7.1
CVE-2025-30158

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the for

7.5
CVE-2025-29784

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s p

7.8
CVE-2025-37838

In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started