Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 568/1469
8.0
CVE-2023-21476

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker

8.0
CVE-2023-21475

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker

8.8
CVE-2025-58176

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9

7.3
CVE-2025-9848

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is

8.8
CVE-2025-58163

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain

7.5
CVE-2025-54588

Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Version

7.3
CVE-2025-9839

A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a

7.3
CVE-2025-9838

A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown functio

7.0
CVE-2025-22442

In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications i

7.3
CVE-2025-22439

In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps

7.8
CVE-2025-22438

In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local

7.8
CVE-2025-22437

In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due

7.8
CVE-2025-22434

In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the

7.8
CVE-2025-22433

In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most common

7.8
CVE-2025-22428

In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on t

7.3
CVE-2025-22427

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above t

7.5
CVE-2025-22423

In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This coul

7.8
CVE-2025-22422

In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app whe

7.3
CVE-2025-22419

In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to

7.8
CVE-2025-22418

In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation o

7.3
CVE-2025-22417

In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacki

7.8
CVE-2025-22416

In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This

7.8
CVE-2024-49730

In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation

7.8
CVE-2024-49720

In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi

7.3
CVE-2024-40653

In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba

7.3
CVE-2025-9837

A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknow

7.3
CVE-2025-9833

A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an u

7.3
CVE-2025-9832

A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown

7.3
CVE-2025-9831

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of t

7.8
CVE-2025-9330

Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerab

7.8
CVE-2025-9329

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo

7.8
CVE-2025-9328

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo

7.8
CVE-2025-9326

Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo

7.3
CVE-2025-9830

A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function

7.8
CVE-2025-9275

Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerab

7.8
CVE-2025-9274

Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulner

7.8
CVE-2025-8614

NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local att

7.2
CVE-2025-8613

Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to

8.8
CVE-2025-8302

Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulne

7.8
CVE-2025-8301

Realtek RTL8811AU rtwlanu.sys N6CSet_DOT11_CIPHER_DEFAULT_KEY Heap-based Buffer Overflow Local Privilege Escalation Vuln

8.8
CVE-2025-8300

Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulne

8.8
CVE-2025-8299

Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation V

7.8
CVE-2025-7976

Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi

7.8
CVE-2025-7975

Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows re

7.5
CVE-2025-7974

rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to

8.8
CVE-2025-6685

ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to esca

7.3
CVE-2025-9829

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown fu

7.8
CVE-2025-9189

There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address w

7.8
CVE-2025-9188

There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitr

7.8
CVE-2025-57778

There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid source address whe

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started