Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 718/1469
7.1
CVE-2025-30578

Cross-Site Request Forgery (CSRF) vulnerability in hotvanrod AdSense Privacy Policy adsense-privacy-policy allows Stored

7.1
CVE-2025-30577

Cross-Site Request Forgery (CSRF) vulnerability in mendibass Browser Address Bar Color browser-address-bar-color allows

7.1
CVE-2025-30572

Cross-Site Request Forgery (CSRF) vulnerability in Igor Yavych Simple Rating simple-rating allows Stored XSS.This issue

7.6
CVE-2025-30571

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in STEdb Corp. STEdb

7.6
CVE-2025-30570

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AliRezaMohammadi د

8.5
CVE-2025-30569

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jahertor WP Featur

7.1
CVE-2025-30565

Cross-Site Request Forgery (CSRF) vulnerability in karrikas banner-manager banner-manager allows Stored XSS.This issue a

7.1
CVE-2025-30564

Cross-Site Request Forgery (CSRF) vulnerability in wpwox Custom Script Integration custom-script-integration allows Stor

7.1
CVE-2025-30561

Cross-Site Request Forgery (CSRF) vulnerability in Henrique Mouta CAS Maestro cas-maestro allows Stored XSS.This issue a

7.1
CVE-2025-30560

Cross-Site Request Forgery (CSRF) vulnerability in Sana Ullah jQuery Dropdown Menu jquery-drop-down-menu-plugin allows S

7.1
CVE-2025-30558

Cross-Site Request Forgery (CSRF) vulnerability in EnzoCostantini55 ANAC XML Render anac-xml-render allows Stored XSS.Th

7.1
CVE-2025-30555

Cross-Site Request Forgery (CSRF) vulnerability in iiiryan WordPres 同步微博 wp2wb allows Stored XSS.This issue affects Word

7.1
CVE-2025-30552

Cross-Site Request Forgery (CSRF) vulnerability in Donald Gilbert WordPress Admin Bar Improved wordpress-admin-bar-impro

7.1
CVE-2025-30550

Cross-Site Request Forgery (CSRF) vulnerability in WPShop.ru CallPhone'r callphoner allows Stored XSS.This issue affects

7.6
CVE-2025-30525

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ProfitShare.ro WP

7.6
CVE-2025-30523

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marcel-NL Super Si

7.1
CVE-2025-30522

Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design cf7-material-design allow

7.8
CVE-2025-0835

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

7.8
CVE-2025-0478

Software installed and run as a non-privileged user may conduct improper GPU system calls to issue reads and writes to a

7.3
CVE-2025-2684

A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. This

7.3
CVE-2025-2683

A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. This vulnerability aff

7.3
CVE-2025-2682

A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. This affects an u

7.3
CVE-2025-2681

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by th

7.3
CVE-2025-2680

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been declared as critical. Affected by

7.3
CVE-2025-2679

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been classified as critical. Affected

7.3
CVE-2025-2678

A vulnerability was found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This issue affects

7.3
CVE-2025-2677

A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. This vulnerab

7.3
CVE-2025-2676

A vulnerability, which was classified as critical, was found in PHPGurukul Bank Locker Management System 1.0. This affec

7.3
CVE-2025-2675

A vulnerability, which was classified as critical, has been found in PHPGurukul Bank Locker Management System 1.0. Affec

7.3
CVE-2025-2674

A vulnerability classified as critical was found in PHPGurukul Bank Locker Management System 1.0. Affected by this vulne

7.3
CVE-2025-2665

A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classified as critical. Th

7.3
CVE-2025-2663

A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected by t

7.3
CVE-2025-2661

A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affec

7.3
CVE-2025-2660

A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulner

7.3
CVE-2025-2659

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This aff

7.3
CVE-2025-2658

A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0

7.3
CVE-2025-2657

A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by

7.3
CVE-2025-2656

A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown fu

7.3
CVE-2025-2655

A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function s

7.8
CVE-2025-29795

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a

7.3
CVE-2025-2654

A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This

8.2
CVE-2025-2691

Versions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can p

7.5
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'res

7.3
CVE-2025-2649

A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerabil

7.3
CVE-2025-2648

A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0. This affects an u

7.3
CVE-2025-2647

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been rated as critical. Affected by th

7.3
CVE-2025-2646

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by

7.3
CVE-2025-2644

A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This issue affects

7.3
CVE-2025-2643

A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerab

7.3
CVE-2025-2642

A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affec

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started