Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 538/1469
7.8
CVE-2025-39949

In the Linux kernel, the following vulnerability has been resolved: qed: Don't collect too many protection override GRC

7.8
CVE-2025-39945

In the Linux kernel, the following vulnerability has been resolved: cnic: Fix use-after-free bugs in cnic_delete_task

7.8
CVE-2025-39944

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix use-after-free bugs in otx2_sync_

7.5
CVE-2025-39942

In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: verify remaining_data_length resp

7.8
CVE-2025-39941

In the Linux kernel, the following vulnerability has been resolved: zram: fix slot write race condition Parallel concu

7.8
CVE-2025-39939

In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Fix memory corruption when using identi

7.8
CVE-2025-39935

In the Linux kernel, the following vulnerability has been resolved: ASoC: codec: sma1307: Fix memory corruption in sma1

7.8
CVE-2025-39931

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_

7.5
CVE-2025-39929

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_neg

8.1
CVE-2025-9243

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa

7.8
CVE-2025-10751

MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi

7.7
CVE-2025-61679

Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained

8.6
CVE-2025-61673

Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent

8.0
CVE-2025-59944

Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the wa

8.1
CVE-2025-59943

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e

8.8
CVE-2025-54374

Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code

7.8
CVE-2025-57714

An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain

8.8
CVE-2025-54153

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

8.8
CVE-2025-53595

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the

7.6
CVE-2025-52656

HCL MyXalytics: 6.6.  is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatica

7.2
CVE-2025-47212

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack

8.8
CVE-2025-44014

An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun

7.1
CVE-2025-61593

Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI

8.8
CVE-2025-61592

Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific

7.6
CVE-2025-52653

HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the exec

7.0
CVE-2025-46817

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user

8.8
CVE-2024-56804

An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, the

8.8
CVE-2025-61591

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit

7.5
CVE-2025-61590

Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R

8.2
CVE-2025-56551

An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo

7.2
CVE-2025-60787

MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name

7.5
CVE-2025-55972

A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni

7.4
CVE-2025-59489

Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi

8.8
CVE-2025-9561

The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic

8.8
CVE-2025-9213

The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due

7.5
CVE-2025-9212

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th

7.5
CVE-2025-9200

The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQ

8.8
CVE-2025-10582

The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and

7.5
CVE-2025-11234

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc

7.8
CVE-2025-11223

Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead

8.2
CVE-2025-0616

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center

7.6
CVE-2025-61597

Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored

8.8
CVE-2025-59536

Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta

7.8
CVE-2025-59300

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta

7.8
CVE-2025-59299

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta

7.8
CVE-2025-59298

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta

7.8
CVE-2025-59297

Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta

7.5
CVE-2025-61600

Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil

7.5
CVE-2025-61665

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken

7.1
CVE-2025-61604

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started