Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 485/1469
7.8
CVE-2023-53795

In the Linux kernel, the following vulnerability has been resolved: iommufd: IOMMUFD_DESTROY should not increase the re

7.8
CVE-2023-53790

In the Linux kernel, the following vulnerability has been resolved: bpf: Zeroing allocated object from slab in bpf memo

8.8
CVE-2023-53785

In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: don't assume adequate headroom for SD

7.8
CVE-2023-53781

In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in tcp_write_timer_handler(

7.8
CVE-2023-53778

In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Clean up integer overflow checking in m

8.1
CVE-2022-50656

In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Clear nfc_target before being used Fix

7.8
CVE-2022-50650

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference state management for synchronous

7.5
CVE-2013-10031

Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks

8.1
CVE-2025-66204

WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in

8.8
CVE-2025-65964

n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to

8.8
CVE-2025-65271

Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te

7.1
CVE-2025-14261

The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only

7.0
CVE-2025-48625

In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen

7.8
CVE-2025-48606

In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi

7.3
CVE-2025-14258

A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno

7.5
CVE-2025-65795

Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create

7.2
CVE-2025-65363

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app

8.8
CVE-2025-63721

HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit

7.3
CVE-2025-48639

In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking

7.8
CVE-2025-48638

In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could

7.8
CVE-2025-48637

In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could l

7.8
CVE-2025-48632

In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the use

7.8
CVE-2025-48629

In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech reco

7.8
CVE-2025-48628

In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused dep

7.8
CVE-2025-48627

In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the

7.8
CVE-2025-48624

In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This c

7.8
CVE-2025-48623

In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could le

7.3
CVE-2025-48621

In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This

7.8
CVE-2025-48620

In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's

7.8
CVE-2025-48615

In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaust

7.8
CVE-2025-48612

In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's defau

7.8
CVE-2025-48599

In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to

7.8
CVE-2025-48597

In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay a

7.8
CVE-2025-48596

In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to lo

7.3
CVE-2025-48594

In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges a

7.5
CVE-2025-48592

In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could l

7.8
CVE-2025-48589

In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due

7.8
CVE-2025-48588

In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This

7.8
CVE-2025-48586

In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to

7.8
CVE-2025-48583

In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the

7.8
CVE-2025-48580

In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in b

7.8
CVE-2025-48575

In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass

7.8
CVE-2025-48573

In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in

7.8
CVE-2025-48572 KEV

In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. Thi

7.8
CVE-2025-48566

In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input

7.8
CVE-2025-48565

In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the cod

7.0
CVE-2025-48564

In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escala

7.8
CVE-2025-48555

In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a con

7.8
CVE-2025-48536

In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to mo

7.8
CVE-2025-48525

In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications wh

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started