Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 738/1469
7.1
CVE-2025-23451

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in titodevera Awesome

7.1
CVE-2025-23450

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in agenwebsite AW Woo

7.1
CVE-2025-23447

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kundan Yevale Smoo

7.1
CVE-2025-23446

Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue

7.1
CVE-2025-23441

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dkukral Attach Gal

7.1
CVE-2025-23439

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willshouse TinyMCE

7.1
CVE-2025-23437

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nord_tramper ntp-h

7.1
CVE-2025-23433

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jnwry vcOS vcos al

7.1
CVE-2025-23425

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marekki Marekkis W

7.8
CVE-2025-21424

Memory corruption while calling the NPU driver APIs concurrently.

8.7
CVE-2025-0475

An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 prior to 17.7.6, 17.8 prior to 17.8.4, an

7.8
CVE-2024-53034

Memory corruption occurs during an Escape call if an invalid Kernel Mode CPU event and sync object handle are passed wit

7.8
CVE-2024-53033

Memory corruption while doing Escape call when user provides valid kernel address in the place of valid user buffer addr

7.8
CVE-2024-53032

Memory corruption may occur in keyboard virtual device due to guest VM interaction.

7.8
CVE-2024-53031

Memory corruption while reading a type value from a buffer controlled by the Guest Virtual Machine.

7.8
CVE-2024-53030

Memory corruption while processing input message passed from FE driver.

7.8
CVE-2024-53029

Memory corruption while reading a value from a buffer controlled by the Guest Virtual Machine.

7.8
CVE-2024-53028

Memory corruption may occur while processing message from frontend during allocation.

7.5
CVE-2024-53027

Transient DOS may occur while processing the country IE.

7.8
CVE-2024-53024

Memory corruption in display driver while detaching a device.

7.8
CVE-2024-53023

Memory corruption may occur while accessing a variable during extended back to back tests.

7.8
CVE-2024-53022

Memory corruption may occur during communication between primary and guest VM.

7.8
CVE-2024-53014

Memory corruption may occur while validating ports and channels in Audio driver.

7.8
CVE-2024-53012

Memory corruption may occur due to improper input validation in clock device.

7.9
CVE-2024-53011

Information disclosure may occur due to improper permission and access controls to Video Analytics engine.

7.8
CVE-2024-49836

Memory corruption may occur during the synchronization of the camera`s frame processing pipeline.

7.8
CVE-2024-45580

Memory corruption while handling multuple IOCTL calls from userspace for remote invocation.

7.8
CVE-2024-43062

Memory corruption caused by missing locks and checks on the DMA fence and improper synchronization.

7.8
CVE-2024-43061

Memory corruption during voice activation, when sound model parameters are loaded from HLOS, and the received sound mode

7.8
CVE-2024-43060

Memory corruption during voice activation, when sound model parameters are loaded from HLOS to ADSP.

7.8
CVE-2024-43059

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

7.8
CVE-2024-43057

Memory corruption while processing command in Glink linux.

7.8
CVE-2024-43055

Memory corruption while processing camera use case IOCTL call.

7.5
CVE-2025-24846

Authentication bypass vulnerability exists in FutureNet AS series (Industrial Routers) provided by Century Systems Co.,

7.1
CVE-2025-24654

Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugi

7.3
CVE-2025-1859

A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some

7.3
CVE-2025-1858

A vulnerability classified as critical was found in Codezips Online Shopping Website 1.0. This vulnerability affects unk

7.3
CVE-2025-1857

A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affe

7.3
CVE-2025-1856

A vulnerability was found in Codezips Gym Management System 1.0. It has been rated as critical. Affected by this issue i

8.1
CVE-2025-1723

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session m

8.8
CVE-2025-1853

A vulnerability was found in Tenda AC8 16.03.34.06 and classified as critical. This issue affects the function sub_49E09

8.8
CVE-2025-1852

A vulnerability has been found in Totolink EX1800T 9.1.0cu.2112_B20220316 and classified as critical. This vulnerability

8.8
CVE-2025-1851

A vulnerability, which was classified as critical, was found in Tenda AC7 up to 15.03.06.44. This affects the function f

7.3
CVE-2025-1850

A vulnerability, which was classified as critical, has been found in Codezips College Management System 1.0. Affected by

7.8
CVE-2025-20645

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio

7.5
CVE-2025-25951

An information disclosure vulnerability in the component /rest/cb/executeBasicSearch of Serosoft Solutions Pvt Ltd Acade

8.1
CVE-2025-25950

Incorrect access control in the component /rest/staffResource/update of Serosoft Solutions Pvt Ltd Academia Student Info

7.3
CVE-2025-1841

A vulnerability classified as critical has been found in ESAFENET CDG 5.6.3.154.205. This affects an unknown part of the

7.3
CVE-2025-1840

A vulnerability was found in ESAFENET CDG 5.6.3.154.205. It has been rated as critical. Affected by this issue is some u

7.8
CVE-2022-49733

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC There

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started