Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 592/1469
7.8
CVE-2025-38747

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio

8.0
CVE-2025-53786

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-sec

7.5
CVE-2025-51532

Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Databa

7.5
CVE-2025-51040

Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html end

8.1
CVE-2025-50286

A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug

8.1
CVE-2025-3354

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i

8.1
CVE-2025-3320

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i

7.5
CVE-2025-23331

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocati

7.5
CVE-2025-23327

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o

7.5
CVE-2025-23326

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o

7.5
CVE-2025-23325

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled

7.5
CVE-2025-23324

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl

7.5
CVE-2025-23323

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl

7.5
CVE-2025-23322

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a doub

7.5
CVE-2025-23321

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero

7.5
CVE-2025-23320

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c

8.1
CVE-2025-23319

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c

8.1
CVE-2025-23318

NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c

7.5
CVE-2025-46390

CWE-204: Observable Response Discrepancy

8.8
CVE-2025-46387

CWE-639 Authorization Bypass Through User-Controlled Key

8.8
CVE-2025-46386

CWE-639 Authorization Bypass Through User-Controlled Key

7.3
CVE-2025-22469

OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions pr

8.1
CVE-2025-7954

A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attack

7.5
CVE-2025-47324

Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

7.8
CVE-2025-27076

Memory corruption while processing simultaneous requests via escape path.

7.8
CVE-2025-27075

Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.

7.5
CVE-2025-27073

Transient DOS while creating NDP instance.

7.3
CVE-2025-27071

Memory corruption while processing specific files in Powerline Communication Firmware.

7.8
CVE-2025-27069

Memory corruption while processing DDI command calls.

7.8
CVE-2025-27068

Memory corruption while processing an IOCTL command with an arbitrary address.

7.8
CVE-2025-27067

Memory corruption while processing DDI call with invalid buffer.

7.5
CVE-2025-27066

Transient DOS while processing an ANQP message.

7.5
CVE-2025-27065

Transient DOS while processing a frame with malformed shared-key descriptor.

7.8
CVE-2025-27062

Memory corruption while handling client exceptions, allowing unauthorized channel access.

7.5
CVE-2025-21477

Transient DOS while processing CCCH data when NW sends data with invalid length.

7.8
CVE-2025-21474

Memory corruption while processing commands from A2dp sink command queue.

7.8
CVE-2025-21473

Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.

7.8
CVE-2025-21461

Memory corruption when programming registers through virtual CDM.

7.8
CVE-2025-21458

Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.

7.8
CVE-2025-21456

Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.

7.8
CVE-2025-21455

Memory corruption while submitting blob data to kernel space though IOCTL.

7.5
CVE-2025-21452

Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.

8.1
CVE-2025-8420

Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code

8.0
CVE-2025-54634

Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of

8.8
CVE-2025-54627

Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect s

8.8
CVE-2025-8654

Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-a

8.8
CVE-2025-8653

Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo

7.5
CVE-2025-7036

The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all vers

8.3
CVE-2025-54622

Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnera

7.3
CVE-2025-54611

EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started