Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 754/1469
8.1
CVE-2024-13770

The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje

7.5
CVE-2024-51376

Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via

8.8
CVE-2024-34520

An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_

7.5
CVE-2024-56940

An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) vi

7.8
CVE-2024-51440

An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.

7.5
CVE-2024-51123

An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensi

7.5
CVE-2024-46923

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a

7.5
CVE-2024-46922

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial

7.5
CVE-2024-41917

Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 ma

7.4
CVE-2024-41168

Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may al

7.8
CVE-2024-39805

Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authent

7.4
CVE-2024-39356

NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23

8.2
CVE-2024-38310

Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentia

7.7
CVE-2024-38307

Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authent

8.8
CVE-2024-37355

Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalat

7.2
CVE-2024-36262

Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user

7.9
CVE-2024-32941

NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potenti

7.8
CVE-2024-31858

Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated us

7.5
CVE-2024-31155

Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentiall

7.5
CVE-2024-29214

Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged use

7.5
CVE-2024-28127

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl

7.5
CVE-2024-24582

Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to

7.5
CVE-2023-49618

Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a p

7.5
CVE-2023-49615

Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a priv

7.5
CVE-2023-49603

Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user

7.9
CVE-2023-48267

Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a p

8.2
CVE-2023-43758

Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enabl

7.5
CVE-2023-34440

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl

8.2
CVE-2023-31276

Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R

7.3
CVE-2023-29164

Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) S

7.8
CVE-2024-12673

An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devic

7.5
CVE-2025-25283

parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1.

8.2
CVE-2025-25205

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a

8.1
CVE-2025-1146

CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the

7.1
CVE-2025-0937

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Poli

7.5
CVE-2025-25200

Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.

7.5
CVE-2025-25199

go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1

7.1
CVE-2025-25198

mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability

7.2
CVE-2025-25743

D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings

7.1
CVE-2024-11629

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, th

8.8
CVE-2025-0556

In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework impleme

7.8
CVE-2025-0332

In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target

8.3
CVE-2024-11343

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can le

8.8
CVE-2025-1244

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execut

8.7
CVE-2025-0376

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 1

7.8
CVE-2024-12251

In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through impro

8.8
CVE-2025-26378

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0

8.1
CVE-2025-26377

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0

8.8
CVE-2025-26375

A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0

7.1
CVE-2025-26372

A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started