Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 574/1469
8.8
CVE-2025-0084

In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code e

7.5
CVE-2025-0081

In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitiali

7.8
CVE-2025-0080

In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overl

7.8
CVE-2025-0079

In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error i

8.8
CVE-2025-0078

In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to loca

8.0
CVE-2023-21125

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This coul

7.3
CVE-2025-9492

A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the fil

7.5
CVE-2025-50971

Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensiti

8.8
CVE-2025-9478

Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap c

7.8
CVE-2025-23315

NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious dat

7.8
CVE-2025-23314

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a

7.8
CVE-2025-23313

NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a

7.8
CVE-2025-23312

NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious da

7.8
CVE-2025-23307

NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow

7.5
CVE-2025-57803

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-

7.5
CVE-2025-55298

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick vers

7.8
CVE-2025-9491

Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote at

7.2
CVE-2025-36729

A non-primary administrator user with admin rights to the web interface but without shell access permissions can display

7.4
CVE-2025-2697

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open

7.8
CVE-2025-1994

IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due t

7.5
CVE-2025-57810

jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage me

8.8
CVE-2025-6366

The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. T

7.5
CVE-2025-52218

SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sani

8.8
CVE-2025-9483

A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1

8.8
CVE-2025-9482

A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.

8.8
CVE-2025-9481

A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.

8.4
CVE-2025-50753

Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "devi

7.5
CVE-2025-29992

Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the data

8.8
CVE-2024-47853

An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w

7.8
CVE-2025-38676

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel

7.8
CVE-2025-53419

Delta Electronics COMMGR has Code Injection vulnerability.

8.6
CVE-2025-53418

Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.

7.3
CVE-2025-9476

A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some u

7.3
CVE-2025-9475

A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unkn

7.3
CVE-2025-9473

A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. This impacts an unknown

7.3
CVE-2025-9472

A vulnerability was found in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of

8.8
CVE-2025-5931

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and

7.3
CVE-2025-9471

A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code

7.3
CVE-2025-9470

A flaw has been found in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /managem

7.3
CVE-2025-9469

A vulnerability was detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown fun

7.3
CVE-2025-9468

A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this vulnerabili

7.5
CVE-2025-9172

The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up

7.3
CVE-2025-9444

A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue af

8.8
CVE-2025-9443

A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /gofor

7.3
CVE-2025-9426

A weakness has been identified in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown par

7.3
CVE-2025-9425

A security flaw has been discovered in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue

7.3
CVE-2025-9423

A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file

7.3
CVE-2025-9421

A vulnerability has been found in itsourcecode Apartment Management System 1.0. This affects an unknown function of the

7.3
CVE-2025-9420

A flaw has been found in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of th

8.8
CVE-2025-8627

The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off conditio

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started