Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 509/1469
7.5
CVE-2025-64458

An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s

7.1
CVE-2025-61084

MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h

7.5
CVE-2025-46784

A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr&#39;ouver

7.5
CVE-2025-46705

A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr&#39;ouvert Lasso 2.5.1 and 2.

7.5
CVE-2025-46404

A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr&#39;ouvert La

8.1
CVE-2025-12497

The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version

8.0
CVE-2025-10622

A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set

8.6
CVE-2025-12384

The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce

7.5
CVE-2025-12139

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv

7.1
CVE-2025-21079

Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL

8.8
CVE-2025-21078

Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a

7.5
CVE-2025-12197

The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15

7.5
CVE-2025-64110

Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen

8.8
CVE-2025-64109

Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta all

8.8
CVE-2025-64108

Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr

8.8
CVE-2025-64107

Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may

8.8
CVE-2025-64106

Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor'

7.5
CVE-2025-59595

CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.

8.8
CVE-2025-62507

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD

7.2
CVE-2025-62369

Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con

7.5
CVE-2025-56230

Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

7.8
CVE-2025-54526

Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted pro

7.8
CVE-2025-54496

A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which ma

7.5
CVE-2025-32786

The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents

7.5
CVE-2024-56426

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,

7.5
CVE-2025-49494

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380,

8.2
CVE-2025-23358

NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path eleme

7.5
CVE-2025-54334

An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. T

7.5
CVE-2025-52513

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results

7.5
CVE-2025-52512

An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results

7.5
CVE-2025-54332

An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Derefe

7.5
CVE-2025-54329

An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 12

7.5
CVE-2025-54323

An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 13

7.5
CVE-2025-41345

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41344

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41343

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41342

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41341

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41340

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41339

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41338

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41337

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41336

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41335

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41114

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41113

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41112

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

7.5
CVE-2025-41111

A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a

8.5
CVE-2025-11690

An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access

8.0
CVE-2025-20742

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started