Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 706/1469
7.1
CVE-2025-31907

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Labib Ahmed Team B

7.1
CVE-2025-31905

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O'Donnell Tea

7.1
CVE-2025-31903

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xavi Ivars XV Rand

7.1
CVE-2025-31902

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems

7.1
CVE-2025-31901

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digihood Digihood

7.1
CVE-2025-31900

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lexicata Lexicata

7.1
CVE-2025-31899

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpshopee Awesome L

7.1
CVE-2025-31898

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dustinscarberry Me

7.1
CVE-2025-31626

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem Supp

7.1
CVE-2025-31582

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani Conta

7.1
CVE-2025-31573

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pepro Dev. Group P

7.1
CVE-2025-31536

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spre

7.1
CVE-2025-31468

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scottsm WP_Identic

7.1
CVE-2025-31467

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miro.mannino Flick

7.1
CVE-2025-31442

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search

7.1
CVE-2025-31436

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Angelo Mandato Blu

7.5
CVE-2025-31098

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2025-30908

Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free web-directory-free allows Stored XSS.This

8.8
CVE-2025-30889

Deserialization of Untrusted Data vulnerability in PickPlugins Testimonial Slider testimonial allows Object Injection.Th

7.1
CVE-2025-30858

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software

7.1
CVE-2025-30616

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Wood Latest

7.1
CVE-2025-30611

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wptobe Wptobe-sign

7.5
CVE-2025-22931

An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unau

7.5
CVE-2024-53868

Apache Traffic Server allows request smuggling if chunked messages are malformed.  This issue affects Apache Traffi

7.3
CVE-2025-3151

A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this i

8.6
CVE-2025-22004

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->s

7.8
CVE-2025-22001

In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix integer overflow in qaic_validate_r

7.8
CVE-2025-21999

In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between

7.3
CVE-2025-3147

A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe

7.3
CVE-2025-3146

A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects

7.3
CVE-2025-3138

A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affect

7.3
CVE-2025-3137

A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Aff

7.0
CVE-2025-2784

A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_ins

8.2
CVE-2025-31479

canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workfl

7.5
CVE-2025-30080

Signalling in Pexip Infinity 29 through 36.2 before 37.0 has improper input validation that allows remote attackers to t

7.5
CVE-2025-2704

OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of se

7.5
CVE-2025-22925

OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendanc

8.8
CVE-2025-22924

OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Stu

8.8
CVE-2025-22923

An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sendin

7.5
CVE-2024-37917

Pexip Infinity before 35.0 has improper input validation that allows remote attackers to trigger a denial of service (so

7.7
CVE-2025-20212

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an a

7.5
CVE-2025-20139

A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo

7.3
CVE-2025-0014

Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege e

7.9
CVE-2024-36337

Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss

7.9
CVE-2024-36336

Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a

7.3
CVE-2024-36328

Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss

8.8
CVE-2025-31722

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protectio

7.6
CVE-2025-21994

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field

8.5
CVE-2024-45064

A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ

7.2
CVE-2025-30090

mime.php in SquirrelMail through 1.4.23-svn-20250401 and 1.5.x through 1.5.2-svn-20250401 allows XSS via e-mail headers,

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started