Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 717/1469
7.8
CVE-2025-22230

VMware Tools for Windows contains an authentication bypass vulnerability due to improper access control. A malicious act

7.5
CVE-2025-1445

A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiat

8.8
CVE-2024-53678

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users

8.8
CVE-2025-2319

The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve

7.2
CVE-2024-13690

The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi

7.3
CVE-2025-2740

A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an u

7.3
CVE-2025-2739

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been rated as critical. This issue af

7.3
CVE-2025-2738

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been declared as critical. This vulne

7.3
CVE-2025-2737

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0. It has been classified as critical. This aff

7.5
CVE-2024-44903

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is ava

7.1
CVE-2024-13863

The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputt

7.2
CVE-2024-13618

The aoa-downloadable WordPress plugin through 0.1.0 lacks authorization and authentication for requests to its download.

8.6
CVE-2024-13617

The aoa-downloadable WordPress plugin through 0.1.0 doesn't validate a parameter in its download function, allowing unau

7.3
CVE-2025-2736

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-2735

A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by

7.3
CVE-2025-2734

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected

8.0
CVE-2025-2732

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014.

8.0
CVE-2025-2731

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014.

8.0
CVE-2025-2730

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014.

8.0
CVE-2025-2729

A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 a

8.0
CVE-2025-2728

A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vul

8.0
CVE-2025-2727

A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unkno

8.0
CVE-2025-2726

A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic

8.0
CVE-2025-2725

A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic B

8.8
CVE-2025-24514

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingr

8.8
CVE-2025-1098

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target`

8.8
CVE-2025-1097

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match

8.1
CVE-2025-29314

Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below

7.5
CVE-2025-29313

Use of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4

7.5
CVE-2025-29311

Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce att

7.8
CVE-2025-2231

PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows re

7.2
CVE-2025-2749 KEV

An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arb

7.6
CVE-2025-30205

kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to ver

7.1
CVE-2025-30112

On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP

7.2
CVE-2025-0255

HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on t

7.3
CVE-2025-2705

A vulnerability classified as critical has been found in Digiwin ERP 5.1. Affected is the function DoUpload/DoWebUpload

7.5
CVE-2021-26091

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Base

7.1
CVE-2025-30621

Cross-Site Request Forgery (CSRF) vulnerability in kornelly Translator translator allows Stored XSS.This issue affects T

7.1
CVE-2025-30620

Cross-Site Request Forgery (CSRF) vulnerability in coderscom WP Odoo Form Integrator wp-odoo-form-integrator allows Stor

7.1
CVE-2025-30612

Cross-Site Request Forgery (CSRF) vulnerability in mandegarweb Replace Default Words replace-default-words allows Stored

7.1
CVE-2025-30608

Cross-Site Request Forgery (CSRF) vulnerability in Anthony WordPress SQL Backup wordpress-sql-backup allows Stored XSS.T

7.6
CVE-2025-30604

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jiangqie JiangQie

7.1
CVE-2025-30603

Cross-Site Request Forgery (CSRF) vulnerability in DEJAN CopyLink copy-link allows Stored XSS.This issue affects CopyLin

7.1
CVE-2025-30602

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alphasis Related P

8.5
CVE-2025-30590

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dourou Flickr set

7.1
CVE-2025-30588

Cross-Site Request Forgery (CSRF) vulnerability in ryan_xantoo Map Contact map-contact allows Stored XSS.This issue affe

7.1
CVE-2025-30587

Cross-Site Request Forgery (CSRF) vulnerability in shawfactor LH OGP Meta lh-ogp-meta-tags allows Stored XSS.This issue

7.1
CVE-2025-30586

Cross-Site Request Forgery (CSRF) vulnerability in bbodine1 cTabs ctabs allows Stored XSS.This issue affects cTabs: from

7.1
CVE-2025-30584

Cross-Site Request Forgery (CSRF) vulnerability in alphaomegaplugins AlphaOmega Captcha & Anti-Spam Filter alphaomega-ca

7.1
CVE-2025-30583

Cross-Site Request Forgery (CSRF) vulnerability in ProRankTracker Pro Rank Tracker proranktracker allows Stored XSS.This

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started