Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

149,356
Total
381
Known Exploited
Showing 79,675 of 149,356 total · Page 913/1594
7.5
CVE-2024-13240

Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu

7.5
CVE-2025-21599

A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Network

7.1
CVE-2025-22814

Cross-Site Request Forgery (CSRF) vulnerability in Dylan James Zephyr Admin Theme zephyr-modern-admin-theme allows Cross

7.1
CVE-2025-22595

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yamna Khawaja Mail

7.1
CVE-2025-22594

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder Better Use

7.1
CVE-2025-22539

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBas

8.5
CVE-2025-22537

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google

8.5
CVE-2025-22535

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal

7.6
CVE-2025-22527

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mail

7.1
CVE-2025-22521

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp H

7.2
CVE-2025-22510

Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Obje

8.1
CVE-2025-22508

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

8.5
CVE-2025-22505

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishli

7.1
CVE-2025-22361

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentr

7.1
CVE-2025-22345

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tsinf TS Comfort D

7.1
CVE-2025-22331

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P3JX Cf7Save Exten

7.1
CVE-2025-22330

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Waghmare MG

7.1
CVE-2025-22313

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetiz

7.1
CVE-2025-22307

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Produ

7.1
CVE-2025-22295

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress

8.2
CVE-2023-24012

An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and

8.2
CVE-2023-24011

An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and

8.2
CVE-2023-24010

An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and

8.8
CVE-2025-0349

A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentContro

8.8
CVE-2024-12848

The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t

8.6
CVE-2024-12542

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl

7.5
CVE-2024-12330

The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit

7.3
CVE-2025-0347

A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulne

7.5
CVE-2024-43660

The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware

7.2
CVE-2024-43659

After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede

8.8
CVE-2024-43657

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje

8.8
CVE-2024-43656

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje

8.8
CVE-2024-43654

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware

8.8
CVE-2024-43653

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Inj

8.8
CVE-2024-43652

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje

8.8
CVE-2024-43649

Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u

8.8
CVE-2024-43648

Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use

7.2
CVE-2024-12805

A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and

7.2
CVE-2024-12803

A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash

8.0
CVE-2023-1907

A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be

7.3
CVE-2025-0340

A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this v

7.8
CVE-2024-53706

A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e

7.5
CVE-2024-53705

A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establis

7.3
CVE-2025-0328

A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by t

7.4
CVE-2025-0306

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attac

7.8
CVE-2024-13206

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part o

7.3
CVE-2024-13200

A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the functio

8.1
CVE-2024-27980

Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line a

7.0
CVE-2025-0283

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7

7.3
CVE-2024-13189

A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file sr

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 149,356 CVE records rated HIGH in our database. Of these, 381 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started