Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 649/1469
7.3
CVE-2025-5553

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnera

7.3
CVE-2025-5551

A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. This affects an unknown part

7.3
CVE-2025-5550

A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown

7.3
CVE-2025-5549

A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is

7.3
CVE-2025-5548

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown functio

7.3
CVE-2025-5547

A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some u

8.8
CVE-2025-5527

A vulnerability was found in Tenda RX3 16.03.13.11_multi_TDE01. It has been rated as critical. This issue affects the fu

8.8
CVE-2025-48999

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists

7.3
CVE-2025-35036

Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input

7.5
CVE-2025-23100

An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. The absence of a NULL check lea

7.8
CVE-2025-23098

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in t

7.3
CVE-2025-5522

A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rate

8.8
CVE-2025-48998

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the p

8.8
CVE-2025-48950

MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution p

8.8
CVE-2025-23102

An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380, 1480 and 2400. A Doub

7.3
CVE-2025-5512

A vulnerability, which was classified as critical, was found in quequnlong shiyi-blog up to 1.2.1. Affected is an unknow

7.3
CVE-2025-30167

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to versio

8.6
CVE-2025-23107

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou

7.2
CVE-2025-25021

IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could all

8.6
CVE-2025-23103

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou

8.8
CVE-2025-5503

A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the func

7.8
CVE-2025-36564

Dell Encryption Admin Utilities versions prior to 11.10.2 contain an Improper Link Resolution vulnerability. A local mal

7.3
CVE-2025-5499

A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function

8.4
CVE-2025-46154

Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

7.3
CVE-2025-5495

A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow

7.5
CVE-2025-4435

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members wo

7.5
CVE-2025-4330

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the

7.5
CVE-2025-4138

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the

7.2
CVE-2025-4392

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Si

8.8
CVE-2025-31359

A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac vers

7.8
CVE-2024-54189

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b

7.8
CVE-2024-52561

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (b

7.8
CVE-2024-36486

A privilege escalation vulnerability exists in the virtual machine archive restoration functionality of Parallels Deskto

7.3
CVE-2025-46355

Incorrect default permissions issue in PC Time Tracer prior to 5.2. If exploited, arbitrary code may be executed with SY

8.6
CVE-2025-21479 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

7.5
CVE-2025-27038 KEV

Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

7.8
CVE-2025-27031

memory corruption while processing IOCTL commands, when the buffer in write loopback mode is accessed after being freed.

7.5
CVE-2025-27029

Transient DOS while processing the tone measurement response buffer when the response buffer is out of range.

7.8
CVE-2025-21486

Memory corruption during dynamic process creation call when client is only passing address and length of shell binary.

7.8
CVE-2025-21485

Memory corruption while processing INIT and multimode invoke IOCTL calls on FastRPC.

8.6
CVE-2025-21480 KEV

Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

7.5
CVE-2025-21463

Transient DOS while processing the EHT operation IE in the received beacon frame.

8.2
CVE-2024-53026

Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.

8.2
CVE-2024-53021

Information disclosure may occur while processing goodbye RTCP packet from network.

8.2
CVE-2024-53020

Information disclosure may occur while decoding the RTP packet with invalid header extension from network.

8.2
CVE-2024-53019

Information disclosure may occur while decoding the RTP packet with improper header length for number of contributing so

7.8
CVE-2024-53010

Memory corruption may occur while attaching VM when the HLOS retains access to VM.

7.2
CVE-2025-4224

The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upl

8.8
CVE-2025-5419 KEV

Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially expl

8.8
CVE-2025-5068

Use after free in Blink in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap co

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started