Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 554/1469
8.8
CVE-2025-10537

Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these b

7.5
CVE-2025-10535

Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed

8.1
CVE-2025-10534

Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

8.8
CVE-2025-10533

Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.

7.3
CVE-2025-10528

Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fi

7.1
CVE-2025-10527

Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F

8.0
CVE-2025-56706

Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter

8.8
CVE-2024-12913

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communicat

7.5
CVE-2025-41249

The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarc

7.5
CVE-2025-41248

The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarch

8.6
CVE-2024-12367

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste

7.1
CVE-2023-53301

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix kernel crash due to null io->bio We shou

8.8
CVE-2023-53297

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap

7.8
CVE-2023-53286

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Return the firmware result upon destroyi

7.1
CVE-2023-53285

In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_v

7.8
CVE-2023-53282

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free KFENCE violation dur

7.8
CVE-2023-53274

In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt8183: Add back SSPM related clocks

7.1
CVE-2023-53272

In the Linux kernel, the following vulnerability has been resolved: net: ena: fix shift-out-of-bounds in exponential ba

7.1
CVE-2023-53265

In the Linux kernel, the following vulnerability has been resolved: ubi: ensure that VID header offset + VID header siz

7.8
CVE-2023-53263

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/disp: fix use-after-free in error handl

7.8
CVE-2025-43372

The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2

8.2
CVE-2025-43371

This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its s

8.8
CVE-2025-43358

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7,

7.8
CVE-2025-43341

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26

7.8
CVE-2025-43340

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl

7.8
CVE-2025-43333

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl

8.2
CVE-2025-43330

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An

8.8
CVE-2025-43329

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe

7.8
CVE-2025-43316

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A ma

7.0
CVE-2025-43304

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.

7.8
CVE-2025-43298

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m

7.1
CVE-2025-43287

The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. Processing a maliciously c

7.8
CVE-2025-43286

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma

7.1
CVE-2025-43263

The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write file

7.8
CVE-2025-43204

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to b

7.5
CVE-2025-31271

This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime cal

7.5
CVE-2025-24088

The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to overrid

8.1
CVE-2025-56274

SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows

7.3
CVE-2025-10482

A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio

7.5
CVE-2025-59056

FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Ad

8.8
CVE-2025-55211

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of

7.3
CVE-2025-10479

A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is

8.6
CVE-2025-59332

3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser funct

7.8
CVE-2025-10203

Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar

7.3
CVE-2025-57248

A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu fil

7.5
CVE-2025-43793

Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202

7.8
CVE-2025-10491

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t

7.3
CVE-2025-10459

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of

7.8
CVE-2023-53262

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix scheduling while atomic in decompression

7.1
CVE-2023-53259

In the Linux kernel, the following vulnerability has been resolved: VMCI: check context->notify_page after call to get_

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started