Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 510/1469
7.8
CVE-2025-20737

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20735

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20733

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es

7.8
CVE-2025-20728

In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local e

8.1
CVE-2025-20727

In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of

7.5
CVE-2025-20726

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation

7.5
CVE-2025-20725

In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalat

7.5
CVE-2025-11890

The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versi

7.2
CVE-2025-11733

The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver

8.8
CVE-2025-11724

The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all

7.5
CVE-2025-11704

The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 v

8.8
CVE-2025-10896

Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of

7.8
CVE-2025-47368

Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing.

7.8
CVE-2025-47367

Memory corruption while accessing a buffer during IOCTL processing.

7.8
CVE-2025-47365

Memory corruption while processing large input data from a remote source via a communication interface.

7.8
CVE-2025-47361

Memory corruption when triggering a subsystem crash with an out-of-range identifier.

7.8
CVE-2025-47360

Memory corruption while processing client message during device management.

8.0
CVE-2025-47357

Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions.

7.8
CVE-2025-47353

Memory corruption while processing request sent from GVM.

7.8
CVE-2025-47352

Memory corruption while processing audio streaming operations.

8.8
CVE-2025-27074

Memory corruption while processing a GP command response.

7.8
CVE-2025-27070

Memory corruption while performing encryption and decryption commands.

8.8
CVE-2025-43505

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing

7.5
CVE-2025-43502

A privacy issue was addressed by removing sensitive data. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1,

7.5
CVE-2025-43500

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.1 and iPadOS 26.

7.5
CVE-2025-43496

The issue was addressed by adding additional logic. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iP

8.1
CVE-2025-43480

The issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe

7.8
CVE-2025-43476

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonom

7.8
CVE-2025-43474

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.2, macOS S

7.8
CVE-2025-43472

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.7.2, macOS So

7.5
CVE-2025-43462

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1

7.5
CVE-2025-43454

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.

7.5
CVE-2025-43450

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPad

7.5
CVE-2025-43449

The issue was addressed with improved handling of caches. This issue is fixed in iOS 26.1 and iPadOS 26.1. A malicious a

7.5
CVE-2025-43436

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS T

8.8
CVE-2025-43433

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2,

8.8
CVE-2025-43431

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2,

8.8
CVE-2025-43419

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tah

7.5
CVE-2025-43413

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, mac

7.8
CVE-2025-43407

This issue was addressed with improved entitlements. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and i

7.5
CVE-2025-43405

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, mac

7.5
CVE-2025-43401

A denial-of-service issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Son

7.5
CVE-2025-43399

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS

7.8
CVE-2025-43387

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe

7.8
CVE-2025-43386

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.2 and iPadOS

7.5
CVE-2025-43376

A logic issue was addressed with improved state management. This issue is fixed in Safari 26, iOS 18.7.7 and iPadOS 18.7

7.5
CVE-2025-43373

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2,

7.8
CVE-2025-43364

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8,

7.8
CVE-2025-43361

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Se

7.1
CVE-2025-43338

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26,

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started