Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 673/1469
8.8
CVE-2025-4345

A vulnerability was found in D-Link DIR-600L up to 2.07B01 and classified as critical. This issue affects the function f

8.8
CVE-2025-4344

A vulnerability, which was classified as critical, was found in D-Link DIR-600L up to 2.07B01. This affects the function

8.1
CVE-2025-46762

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute ar

7.5
CVE-2025-2011

The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the ‘s' parameter

8.8
CVE-2025-4343

A vulnerability has been found in D-Link DIR-600L up to 2.07B01 and classified as critical. This vulnerability affects t

8.8
CVE-2025-4342

A vulnerability, which was classified as critical, has been found in D-Link DIR-600L up to 2.07B01. Affected by this iss

7.8
CVE-2025-21475

Memory corruption while processing escape code, when DisplayId is passed with large unsigned value.

7.8
CVE-2025-21470

Memory corruption while processing image encoding, when configuration is NULL in IOCTL parameter.

7.8
CVE-2025-21469

Memory corruption while processing image encoding, when input buffer length is 0 in IOCTL call.

7.8
CVE-2025-21468

Memory corruption while reading response from FW, when buffer size is changed by FW while driver is using this size to w

7.8
CVE-2025-21467

Memory corruption while reading the FW response from the shared queue.

7.8
CVE-2025-21462

Memory corruption while processing an IOCTL request, when buffer significantly exceeds the command argument limit.

7.8
CVE-2025-21460

Memory corruption while processing a message, when the buffer is controlled by a Guest VM, the value can be changed cont

7.5
CVE-2025-21459

Transient DOS while parsing per STA profile in ML IE.

7.8
CVE-2025-21453

Memory corruption while processing a data structure, when an iterator is accessed after it has been removed, potential f

7.5
CVE-2024-49847

Transient DOS while processing of a registration acceptance OTA due to incorrect ciphering key data IE.

8.2
CVE-2024-49846

Memory corruption while decoding of OTA messages from T3448 IE.

7.8
CVE-2024-49845

Memory corruption during the FRS UDS generation process.

7.8
CVE-2024-49844

Memory corruption while triggering commands in the PlayReady Trusted application.

7.8
CVE-2024-49842

Memory corruption during memory mapping into protected VM address space due to incorrect API restrictions.

7.8
CVE-2024-49841

Memory corruption during memory assignment to headless peripheral VM due to incorrect error code handling.

7.8
CVE-2024-49835

Memory corruption while reading secure file.

7.8
CVE-2024-45579

Memory corruption may occur when invoking IOCTL calls from userspace to the camera kernel driver to dump request informa

7.8
CVE-2024-45578

Memory corruption while acquire and update IOCTLs during IFE output resource ID validation.

7.8
CVE-2024-45577

Memory corruption while invoking IOCTL calls from userspace to camera kernel driver to dump request information.

7.8
CVE-2024-45576

Memory corruption while prociesing command buffer buffer in OPE module.

7.8
CVE-2024-45575

Memory corruption Camera kernel when large number of devices are attached through userspace.

7.8
CVE-2024-45574

Memory corruption during array access in Camera kernel due to invalid index from invalid command data.

7.8
CVE-2024-45567

Memory corruption while encoding JPEG format.

7.8
CVE-2024-45566

Memory corruption during concurrent buffer access due to modification of the reference count.

7.8
CVE-2024-45565

Memory corruption when blob structure is modified by user-space after kernel verification.

7.8
CVE-2024-45564

Memory corruption during concurrent access to server info object due to incorrect reference count update.

7.8
CVE-2024-45554

Memory corruption during concurrent SSR execution due to race condition on the global maps list.

7.3
CVE-2025-4332

A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by th

7.3
CVE-2025-4331

A vulnerability classified as critical was found in SourceCodester Online Student Clearance System 1.0. This vulnerabili

7.5
CVE-2025-46585

Out-of-bounds array read/write vulnerability in the kernel module Impact: Successful exploitation of this vulnerability

7.8
CVE-2025-46584

Vulnerability of improper authentication logic implementation in the file system module Impact: Successful exploitation

7.3
CVE-2025-4314

A vulnerability has been found in SourceCodester Advanced Web Store 1.0 and classified as critical. Affected by this vul

7.3
CVE-2025-4313

A vulnerability, which was classified as critical, was found in SourceCodester Advanced Web Store 1.0. Affected is an un

7.3
CVE-2025-2802

The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,

7.3
CVE-2025-4312

A vulnerability, which was classified as critical, has been found in SourceCodester Advanced Web Store 1.0. This issue a

7.3
CVE-2025-4311

A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affec

7.3
CVE-2025-4309

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been rated as critical. Affected by th

7.3
CVE-2025-4308

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by

7.3
CVE-2025-4307

A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been classified as critical. Affected

7.3
CVE-2025-4306

A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue

8.8
CVE-2025-3610

The Reales WP STPT plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to

7.3
CVE-2025-4304

A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affect

7.3
CVE-2025-4303

A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management

7.3
CVE-2025-4301

A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnera

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started