Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 705/1469
7.2
CVE-2024-13708

The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve

7.3
CVE-2025-3197

Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index

7.5
CVE-2025-3194

Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attacke

8.2
CVE-2025-3192

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl

8.8
CVE-2025-2075

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to

8.1
CVE-2024-13744

The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida

7.3
CVE-2025-3202

A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function o

7.3
CVE-2025-3199

A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unk

7.3
CVE-2025-3195

A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.

7.3
CVE-2025-3188

A vulnerability classified as critical has been found in PHPGurukul e-Diary Management System 1.0. This affects an unkno

7.3
CVE-2025-3187

A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been rated as critical. Affected by this i

7.6
CVE-2025-29815

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

8.8
CVE-2025-25000

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized

7.3
CVE-2025-3186

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critica

7.3
CVE-2025-3185

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as criti

7.3
CVE-2025-3184

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This

7.3
CVE-2025-3183

A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical.

7.3
CVE-2025-3182

A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1

7.3
CVE-2025-3181

A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking Sys

7.4
CVE-2025-30370

jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Gi

7.3
CVE-2025-3180

A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected

7.3
CVE-2025-3179

A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Aff

7.3
CVE-2025-3178

A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical.

7.5
CVE-2024-56528

This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establish

7.5
CVE-2024-47215

An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an in

7.5
CVE-2024-47214

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind

7.5
CVE-2024-47213

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to th

7.5
CVE-2024-47212

An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API end

8.8
CVE-2024-45199

insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param

7.3
CVE-2025-3176

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. Thi

7.5
CVE-2025-31485

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL g

7.5
CVE-2025-31481

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you c

7.6
CVE-2025-31119

generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generato

7.8
CVE-2025-29570

An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via t

7.8
CVE-2025-29504

Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe perm

8.8
CVE-2024-45198

insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i

7.3
CVE-2025-3175

A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by

7.3
CVE-2025-3174

A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affecte

7.3
CVE-2025-3173

A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affe

7.7
CVE-2025-31487

The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If th

7.3
CVE-2025-3172

A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0.

7.3
CVE-2025-3171

A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerabili

7.3
CVE-2025-3170

A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affect

7.3
CVE-2025-3168

A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by t

8.8
CVE-2025-29987

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficie

8.8
CVE-2024-4877

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi

8.8
CVE-2025-3161

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function Shutdown

7.4
CVE-2025-3155

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vu

7.5
CVE-2025-32049

A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup t

7.5
CVE-2025-31909

Missing Authorization vulnerability in Apptivo Apptivo Business Site CRM apptivo-business-site allows Exploiting Incorre

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started