Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 441/1469
7.8
CVE-2025-71110

In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc

7.1
CVE-2025-71109

In the Linux kernel, the following vulnerability has been resolved: MIPS: ftrace: Fix memory corruption when kernel is

8.6
CVE-2026-0532

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker

7.9
CVE-2025-0647

In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a

7.5
CVE-2025-14770

The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions

7.2
CVE-2025-15378

The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup

7.2
CVE-2025-15283

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and

7.2
CVE-2025-15266

The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto

7.1
CVE-2025-14615

The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request

7.2
CVE-2025-14613

The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu

7.8
CVE-2025-68968

Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affe

8.4
CVE-2025-68960

Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnera

8.0
CVE-2025-68958

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab

8.4
CVE-2025-68957

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab

8.0
CVE-2025-68956

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab

8.0
CVE-2025-68955

Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnera

7.8
CVE-2025-12053

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-

7.8
CVE-2025-12052

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-

7.8
CVE-2025-12051

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-

7.8
CVE-2025-12050

The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-

8.2
CVE-2023-54340

WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by mani

8.4
CVE-2023-54338

Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit

8.4
CVE-2023-54336

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to

8.2
CVE-2023-54333

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attac

7.8
CVE-2023-54331

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra

8.4
CVE-2023-53984

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca

7.2
CVE-2022-50939

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to overrid

8.4
CVE-2022-50938

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with

8.8
CVE-2022-50936

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload mal

7.8
CVE-2022-50933

Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar

7.5
CVE-2022-50932

Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attack

7.8
CVE-2022-50931

TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable fi

8.4
CVE-2022-50930

Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows

8.4
CVE-2022-50929

Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows

7.8
CVE-2022-50928

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows lo

8.4
CVE-2022-50924

Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execu

7.8
CVE-2022-50923

Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with

7.8
CVE-2022-50921

WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra

8.4
CVE-2022-50920

Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local a

8.4
CVE-2022-50918

VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrar

7.8
CVE-2022-50917

ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows loca

7.2
CVE-2022-50916

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server

7.8
CVE-2022-50915

PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers t

8.4
CVE-2022-50914

EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. A

8.4
CVE-2022-50913

ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code

8.8
CVE-2022-50909

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows

7.2
CVE-2022-50908

Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts thr

7.2
CVE-2022-50907

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upl

8.4
CVE-2022-50904

Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute

8.4
CVE-2022-50903

Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started