Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 556/1469
7.8
CVE-2023-53179

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add the missing IP_SET_HASH_WITH_

7.8
CVE-2023-53178

In the Linux kernel, the following vulnerability has been resolved: mm: fix zswap writeback race condition The zswap w

7.8
CVE-2023-53176

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Reinit port->pm on port specific driv

7.8
CVE-2023-53170

In the Linux kernel, the following vulnerability has been resolved: net: dsa: Removed unneeded of_node_put in felix_par

7.8
CVE-2023-53153

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Fix use after free for wext Key in

7.8
CVE-2023-53148

In the Linux kernel, the following vulnerability has been resolved: igb: Fix igb_down hung on surprise removal In a se

7.8
CVE-2022-50259

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: fix race in sock_map_free() sock_map

7.8
CVE-2022-50258

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential stack-out-of-bounds i

7.8
CVE-2022-50256

In the Linux kernel, the following vulnerability has been resolved: drm/meson: remove drm bridges at aggregate driver u

7.8
CVE-2022-50255

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix reading strings from synthetic events

7.8
CVE-2022-50252

In the Linux kernel, the following vulnerability has been resolved: igb: Do not free q_vector unless new one was alloca

7.8
CVE-2022-50248

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix double free on tx path. We

7.8
CVE-2022-50245

In the Linux kernel, the following vulnerability has been resolved: rapidio: fix possible UAF when kfifo_alloc() fails

7.8
CVE-2022-50243

In the Linux kernel, the following vulnerability has been resolved: sctp: handle the error returned from sctp_auth_asoc

8.8
CVE-2022-50241

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix use-after-free on source server when doin

7.8
CVE-2022-50240

In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA

7.1
CVE-2022-50239

In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom: fix writes in read-only memory regio

7.8
CVE-2022-50234

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: defer registered files gc to io_u

7.3
CVE-2025-3025

Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local use

7.5
CVE-2025-39804

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm64/poly1305: Fix register corruption

7.8
CVE-2025-39803

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from uf

7.5
CVE-2025-39802

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: arm/poly1305: Fix register corruption i

7.8
CVE-2025-39800

In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on unexpected eb generatio

7.3
CVE-2025-10446

A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. The affected element is

7.3
CVE-2025-10445

A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. Impacted is an unknown function of

7.5
CVE-2025-59358

The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kuber

7.3
CVE-2025-10444

A security flaw has been discovered in Campcodes Online Job Finder System 1.0. This issue affects some unknown processin

8.8
CVE-2025-10443

A vulnerability was identified in Tenda AC9 and AC15 15.03.05.14/15.03.05.18. This vulnerability affects the function fo

7.6
CVE-2025-9072

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, a

7.3
CVE-2025-10436

A weakness has been identified in Campcodes Computer Sales and Inventory System 1.0. The impacted element is an unknown

7.3
CVE-2025-10435

A security flaw has been discovered in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unk

7.3
CVE-2025-10426

A security flaw has been discovered in itsourcecode Online Laundry Management System 1.0. This affects an unknown functi

7.3
CVE-2025-10425

A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The i

7.3
CVE-2025-10424

A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The a

7.5
CVE-2025-59375

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is

7.3
CVE-2025-10417

A security flaw has been discovered in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function

7.3
CVE-2025-10416

A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of

7.3
CVE-2025-10415

A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of

7.3
CVE-2025-10414

A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. The impacted element is an unknown functi

7.3
CVE-2025-10413

A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. The affected element is an unknown f

7.3
CVE-2025-10405

A vulnerability was determined in itsourcecode Baptism Information Management System 1.0. Affected is an unknown functio

7.3
CVE-2025-10404

A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of

7.3
CVE-2025-10403

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function of t

7.3
CVE-2025-10402

A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of

7.3
CVE-2025-10396

A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. Affected by this issue is some un

7.7
CVE-2025-59363

In One Identity OneLogin before 2025.3.0, a request returns the OIDC client secret with GET Apps API v2 (even though thi

8.8
CVE-2025-10385

A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1.1. Affected by this issue is the function sub_450B

7.3
CVE-2025-10374

A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11. This affects an unknown part of t

7.3
CVE-2025-10371

A security flaw has been discovered in eCharge Hardy Barth Salia PLCC up to 2.3.81. This issue affects some unknown proc

7.3
CVE-2025-10359

A vulnerability was detected in Wavlink WL-WN578W2 221110. This impacts the function sub_404DBC of the file /cgi-bin/wir

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started