Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 650/1469
7.8
CVE-2025-23105

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processo

8.8
CVE-2025-1051

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent

7.5
CVE-2025-27956

Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via th

8.0
CVE-2025-20298

In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to

7.8
CVE-2025-5036

A maliciously crafted RFA file, when linked or imported into Autodesk Revit, can force a Use-After-Free vulnerability. A

7.2
CVE-2025-48940

MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input

7.5
CVE-2025-48866

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions

7.3
CVE-2025-45542

SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is v

7.3
CVE-2024-57459

A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds

8.4
CVE-2024-54028

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially cra

8.4
CVE-2024-52035

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95.

8.4
CVE-2024-48877

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility vers

7.2
CVE-2025-37091

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

8.1
CVE-2024-57783

The desktop application in Dot through 0.9.3 allows XSS and resultant command execution because user input and LLM outpu

7.8
CVE-2025-26396

The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escal

7.8
CVE-2024-12168

Yandex Telemost for Desktop before 2.7.0 has a DLL Hijacking Vulnerability because an untrusted search path is used.

7.5
CVE-2025-48957

AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions

7.5
CVE-2025-29785

quic-go is an implementation of the QUIC protocol in Go. The loss recovery logic for path probe packets that was added i

7.8
CVE-2025-1246

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace D

7.8
CVE-2025-0819

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge

7.8
CVE-2025-0073

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al

8.3
CVE-2025-3260

A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard a

7.3
CVE-2025-5435

A vulnerability was found in Marwal Infotech CMS 1.0. It has been declared as critical. This vulnerability affects unkno

8.8
CVE-2025-0358

During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi

7.3
CVE-2025-5434

A vulnerability was found in Aem Solutions CMS up to 1.0. It has been classified as critical. This affects an unknown pa

7.8
CVE-2025-25179

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to

7.8
CVE-2024-11857

Bluetooth HCI Adaptor from Realtek has a Link Following vulnerability. Local attackers with regular privileges can creat

7.3
CVE-2025-5409

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the fu

7.3
CVE-2025-5402

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as

7.3
CVE-2025-5401

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been declared

7.3
CVE-2025-5400

A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been classifi

7.3
CVE-2025-5376

A vulnerability was found in SourceCodester Health Center Patient Record Management System 1.0. It has been declared as

7.2
CVE-2025-4857

The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9

7.3
CVE-2025-5371

A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Managem

8.8
CVE-2025-4672

The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization plac

8.8
CVE-2025-4103

The WP-GeoMeta plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the wp_aj

7.3
CVE-2025-5370

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. Affected by this vulnerability is an unk

7.3
CVE-2025-5369

A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0. Affected i

7.3
CVE-2025-5367

A vulnerability was found in PHPGurukul Online Shopping Portal Project 1.0. It has been declared as critical. This vulne

7.3
CVE-2025-5365

A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been classified as critical. This a

7.3
CVE-2025-5364

A vulnerability was found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by thi

7.3
CVE-2025-5363

A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected b

7.3
CVE-2025-5362

A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte

7.3
CVE-2025-5361

A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. Th

7.3
CVE-2025-5360

A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability

7.1
CVE-2025-2503

An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to per

7.8
CVE-2025-2502

An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to ele

7.8
CVE-2025-2501

An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate pr

7.3
CVE-2025-5359

A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects a

7.3
CVE-2025-5358

A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affec

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started