Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 703/1469
8.8
CVE-2024-11071

Permissive Cross-domain Policy with Untrusted Domains vulnerability in local API server of DestinyECM solution(versions

7.3
CVE-2025-3337

A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been rated as critical. This i

7.3
CVE-2025-3336

A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Thi

7.3
CVE-2025-3335

A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. T

7.3
CVE-2025-3334

A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affected b

8.4
CVE-2025-31175

Deserialization mismatch vulnerability in the DSoftBus module Impact: Successful exploitation of this vulnerability may

8.8
CVE-2025-31173

Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab

7.8
CVE-2025-31172

Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab

8.4
CVE-2025-31170

Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w

7.5
CVE-2025-20664

In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (p

7.5
CVE-2025-20663

In wlan AP driver, there is a possible information disclosure due to an uncaught exception. This could lead to remote (p

8.4
CVE-2024-58127

Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w

8.4
CVE-2024-58126

Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w

8.4
CVE-2024-58125

Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w

8.4
CVE-2024-58124

Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w

7.5
CVE-2024-58112

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation

7.5
CVE-2024-58111

Exception capture failure vulnerability in the SVG parsing module of the ArkUI framework Impact: Successful exploitation

7.5
CVE-2024-58107

Buffer overflow vulnerability in the codec module Impact: Successful exploitation of this vulnerability may affect avail

7.3
CVE-2025-3333

A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. Affec

7.3
CVE-2025-3332

A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. Af

7.3
CVE-2025-3331

A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.

7.3
CVE-2025-3330

A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. This vulnerabi

8.8
CVE-2025-3328

A vulnerability was found in Tenda AC1206 15.03.06.23. It has been classified as critical. Affected is the function form

7.5
CVE-2025-32013

LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered

7.5
CVE-2025-2260

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of s

7.5
CVE-2025-2259

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer un

7.5
CVE-2025-2258

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause

7.3
CVE-2025-3316

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affec

7.3
CVE-2025-3315

A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected

7.3
CVE-2025-3314

A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Aff

7.3
CVE-2025-3313

A vulnerability, which was classified as critical, was found in PHPGurukul Men Salon Management System 1.0. Affected is

7.3
CVE-2025-3312

A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This is

7.3
CVE-2025-3311

A vulnerability classified as critical was found in PHPGurukul Men Salon Management System 1.0. This vulnerability affec

7.2
CVE-2025-32370

Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uplo

7.3
CVE-2025-3310

A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an

7.3
CVE-2025-3309

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by

7.3
CVE-2025-3308

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected

7.3
CVE-2025-3307

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affecte

7.3
CVE-2025-3306

A vulnerability was found in code-projects Blood Bank Management System 1.0 and classified as critical. This issue affec

7.3
CVE-2025-3299

A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this iss

8.1
CVE-2024-13776

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modificati

8.8
CVE-2025-2933

The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lea

7.5
CVE-2025-0810

The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in

7.5
CVE-2024-13604

The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to

7.3
CVE-2025-3266

A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this

7.3
CVE-2025-3265

A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. Affected by this vulnerabi

8.8
CVE-2025-3259

A vulnerability, which was classified as critical, has been found in Tenda RX3 16.03.13.11. This issue affects the funct

8.1
CVE-2024-11235

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and

7.3
CVE-2025-3258

A vulnerability classified as critical was found in PHPGurukul Old Age Home Management System 1.0. This vulnerability af

7.6
CVE-2025-32204

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in rocketelements Spl

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started