Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 702/1469
7.3
CVE-2025-3374

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f

7.3
CVE-2025-3373

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a

8.8
CVE-2025-28409

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endp

8.8
CVE-2025-28407

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endp

7.2
CVE-2025-28403

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly vali

7.3
CVE-2025-3372

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function

7.3
CVE-2025-3371

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk

7.3
CVE-2025-3370

A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unk

7.5
CVE-2025-30195

An attacker can publish a zone containing specific Resource Record Sets. Processing and caching results for these sets c

7.3
CVE-2025-3353

A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. This affect

7.3
CVE-2025-3352

A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this

7.3
CVE-2025-3351

A vulnerability has been found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by

7.3
CVE-2025-3350

A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected

7.3
CVE-2025-3349

A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk

7.5
CVE-2025-21448

Transient DOS may occur while parsing SSID in action frames.

7.8
CVE-2025-21447

Memory corruption may occur while processing device IO control call for session control.

7.8
CVE-2025-21443

Memory corruption while processing message content in eAVB.

7.8
CVE-2025-21442

Memory corruption while transmitting packet mapping information with invalid header payload size.

7.8
CVE-2025-21441

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

7.8
CVE-2025-21440

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

7.8
CVE-2025-21439

Memory corruption may occur while reading board data via IOCTL call when the WLAN driver copies the content to the provi

7.8
CVE-2025-21438

Memory corruption while IOCTL call is invoked from user-space to read board data.

7.8
CVE-2025-21437

Memory corruption while processing memory map or unmap IOCTL operations simultaneously.

7.8
CVE-2025-21436

Memory corruption may occur while initiating two IOCTL calls simultaneously to create processes from two different threa

7.5
CVE-2025-21435

Transient DOS may occur while parsing extended IE in beacon.

7.5
CVE-2025-21434

Transient DOS may occur while parsing EHT operation IE or EHT capability IE.

7.5
CVE-2025-21430

Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session.

7.5
CVE-2025-21429

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request.

7.5
CVE-2025-21428

Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSp

7.3
CVE-2025-21425

Memory corruption may occur due top improper access control in HAB process.

7.8
CVE-2025-21423

Memory corruption occurs when handling client calls to EnableTestMode through an Escape call.

7.8
CVE-2025-21421

Memory corruption while processing escape code in API.

7.8
CVE-2024-45557

Memory corruption can occur when TME processes addresses from TZ and MPSS requests without proper validation.

8.2
CVE-2024-45552

Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t

7.7
CVE-2024-45549

Information disclosure while creating MQ channels.

7.8
CVE-2024-43067

Memory corruption occurs during the copying of read data from the EEPROM because the IO configuration is exposed as shar

7.8
CVE-2024-43066

Memory corruption while handling file descriptor during listener registration/de-registration.

7.1
CVE-2024-43065

Cryptographic issues while generating an asymmetric key pair for RKP use cases.

7.8
CVE-2024-43058

Memory corruption while processing IOCTL calls.

7.5
CVE-2024-33058

Memory corruption while assigning memory from the source DDR memory(HLOS) to ADSP.

8.8
CVE-2025-3346

A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. Affected by this issue is the functio

7.3
CVE-2025-3345

A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been declared as critical. Aff

7.3
CVE-2025-3344

A vulnerability was found in codeprojects Online Restaurant Management System 1.0. It has been classified as critical. A

8.8
CVE-2025-30473

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Com

7.3
CVE-2025-3343

A vulnerability was found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This issue

7.3
CVE-2025-3342

A vulnerability has been found in codeprojects Online Restaurant Management System 1.0 and classified as critical. This

7.3
CVE-2025-3341

A vulnerability, which was classified as critical, was found in codeprojects Online Restaurant Management System 1.0. Th

7.3
CVE-2025-3340

A vulnerability, which was classified as critical, has been found in codeprojects Online Restaurant Management System 1.

7.3
CVE-2025-3339

A vulnerability classified as critical was found in codeprojects Online Restaurant Management System 1.0. Affected by th

7.3
CVE-2025-3338

A vulnerability classified as critical has been found in codeprojects Online Restaurant Management System 1.0. Affected

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started