Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 618/1469
7.8
CVE-2025-50130

A heap-based buffer overflow vulnerability exists in VS6Sim.exe contained in V-SFT and TELLUS provided by FUJI ELECTRIC

7.8
CVE-2025-27061

Memory corruption whhile handling the subsystem failure memory during the parsing of video packets received from the vid

7.8
CVE-2025-27058

Memory corruption while processing packet data with exceedingly large packet.

7.5
CVE-2025-27057

Transient DOS while handling beacon frames with invalid IE header length.

7.8
CVE-2025-27056

Memory corruption during sub-system restart while processing clean-up to free up resources.

7.8
CVE-2025-27055

Memory corruption during the image encoding process.

7.8
CVE-2025-27052

Memory corruption while processing data packets in diag received from Unix clients.

7.8
CVE-2025-27051

Memory corruption while processing command message in WLAN Host.

7.8
CVE-2025-27050

Memory corruption while processing event close when client process terminates abruptly.

7.8
CVE-2025-27047

Memory corruption while processing the TESTPATTERNCONFIG escape path.

7.8
CVE-2025-27046

Memory corruption while processing multiple simultaneous escape calls.

7.8
CVE-2025-27044

Memory corruption while executing timestamp video decode command with large input values.

7.8
CVE-2025-27043

Memory corruption while processing manipulated payload in video firmware.

7.8
CVE-2025-27042

Memory corruption while processing video packets received from video firmware.

7.8
CVE-2025-21466

Memory corruption while processing a private escape command in an event trigger.

7.5
CVE-2025-21454

Transient DOS while processing received beacon frame.

7.5
CVE-2025-21449

Transient DOS may occur while processing malformed length field in SSID IEs.

7.5
CVE-2025-21446

Transient DOS may occur when processing vendor-specific information elements while parsing a WLAN frame for BTM requests

7.8
CVE-2025-21445

Memory corruption while copying the result to the transmission queue which is shared between the virtual machine and the

7.8
CVE-2025-21444

Memory corruption while copying the result to the transmission queue in EMAC.

7.8
CVE-2025-21432

Memory corruption while retrieving the CBOR data from TA.

8.2
CVE-2025-21427

Information disclosure while decoding this RTP packet Payload when UE receives the RTP packet from the network.

7.1
CVE-2025-21422

Cryptographic issue while processing crypto API calls, missing checks may lead to corrupted key usage or IV reuses.

7.3
CVE-2025-7176

A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been declared as critical. Affected by th

7.5
CVE-2025-40718

Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows

7.3
CVE-2025-7174

A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknow

8.8
CVE-2025-41224

A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.0), RUGGEDCOM RMC8388NC V5.X (All ve

7.8
CVE-2025-40741

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications con

7.8
CVE-2025-40740

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications con

7.8
CVE-2025-40739

A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 5). The affected applications con

8.8
CVE-2025-40738

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly valid

8.8
CVE-2025-40737

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected application does not properly valid

8.8
CVE-2025-40735

A vulnerability has been identified in SINEC NMS (All versions < V4.0). The affected devices are vulnerable to SQL injec

7.8
CVE-2025-23365

A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-pr

7.0
CVE-2025-21006

Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attacke

8.1
CVE-2024-31854

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect

8.1
CVE-2024-31853

A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.11). During establishment of a https connect

7.0
CVE-2023-52236

A vulnerability has been identified in RUGGEDCOM i800 (All versions), RUGGEDCOM i801 (All versions), RUGGEDCOM i802 (All

7.3
CVE-2025-7173

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affect

7.3
CVE-2025-7172

A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects a

7.3
CVE-2025-6744

The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including

7.3
CVE-2025-7171

A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected

7.3
CVE-2025-7170

A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerabi

7.3
CVE-2025-7169

A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknow

7.3
CVE-2025-7168

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects

7.8
CVE-2025-38236

In the Linux kernel, the following vulnerability has been resolved: af_unix: Don't leave consecutive consumed OOB skbs.

8.8
CVE-2025-6746

The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via

8.8
CVE-2025-41668

A low privileged remote attacker with file access can replace a critical file or folder used by the service security-pro

8.8
CVE-2025-41667

A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read

8.8
CVE-2025-41666

A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write an

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started