Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 545/1469
8.6
CVE-2025-10438

Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical

7.5
CVE-2025-59833

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/probl

7.5
CVE-2025-57319

fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedR

7.5
CVE-2025-57318

A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject prop

7.5
CVE-2025-57329

web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability i

7.5
CVE-2025-57328

toggle-array is a package designed to enables a property on the object at the specified index, while disabling the prope

7.5
CVE-2025-57327

spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config funct

7.5
CVE-2025-57326

A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers

7.5
CVE-2025-57325

rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes a

7.5
CVE-2025-57323

mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vul

7.6
CVE-2025-59251

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

7.5
CVE-2025-57349

The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable

7.5
CVE-2025-57330

The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in

7.3
CVE-2025-55322

Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.

7.6
CVE-2025-59305

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use

8.6
CVE-2025-57350

The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototy

7.5
CVE-2025-56241

Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the

8.8
CVE-2025-52907

Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect

7.5
CVE-2025-48869

Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res

7.7
CVE-2025-20352 KEV

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa

7.7
CVE-2025-20327

A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to

8.6
CVE-2025-20315

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau

7.7
CVE-2025-20312

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe

7.4
CVE-2025-20311

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co

8.1
CVE-2025-20160

A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo

8.8
CVE-2025-56816

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack

7.1
CVE-2025-56815

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses

8.8
CVE-2025-20334

A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that

8.8
CVE-2025-10892

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2025-10891

Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co

8.8
CVE-2025-10502

Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit

8.8
CVE-2025-10501

Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap

8.8
CVE-2025-10500

Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co

7.8
CVE-2025-47329

Memory corruption while handling invalid inputs in application info setup.

7.5
CVE-2025-47328

Transient DOS while processing power control requests with invalid antenna or stream values.

7.8
CVE-2025-47327

Memory corruption while encoding the image data.

7.5
CVE-2025-47326

Transient DOS while handling command data during power control processing.

7.5
CVE-2025-47318

Transient DOS while parsing the EPTM test control message to get the test pattern.

7.8
CVE-2025-47317

Memory corruption due to global buffer overflow when a test command uses an invalid payload type.

7.8
CVE-2025-47316

Memory corruption due to double free when multiple threads race to set the timestamp store.

7.8
CVE-2025-47315

Memory corruption while handling repeated memory unmap requests from guest VM.

7.8
CVE-2025-47314

Memory corruption while processing data sent by FE driver.

7.8
CVE-2025-27077

Memory corruption while processing message in guest VM.

7.8
CVE-2025-27037

Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.

7.8
CVE-2025-27032

memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache

8.2
CVE-2025-21488

Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se

8.2
CVE-2025-21487

Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great

8.2
CVE-2025-21484

Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f

7.1
CVE-2025-21482

Cryptographic issue while performing RSA PKCS padding decoding.

7.8
CVE-2025-21481

Memory corruption while performing private key encryption in trusted application.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started