A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connectio
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Rust bindings. This issue affects A
Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_glib, Go, netstd, Delphi and Haxe bindings. This i
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This iss
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift C++ bindings. This issue affects A
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects A
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Thrift Python, Go, PHP and Java bindings.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This i
In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only acc
A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vul
cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. Th
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip(
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conver
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco
In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action at
Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission cal
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session
The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registrat
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t
In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IO
In the Linux kernel, the following vulnerability has been resolved: drm/hyperv: validate resolution_count and fix WIN8
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix eswitch mode block underflow on IPse
In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS co
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce1: Fix VCE 1 firmware size and offset
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix MLE defragmentation If either
In the Linux kernel, the following vulnerability has been resolved: ACPI: NFIT: core: Fix acpi_nfit_init() error cleanu
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix clear_pending_event f
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and
In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_event_g
In the Linux kernel, the following vulnerability has been resolved: ALSA: virtio: Validate control metadata from the de
In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs35l41: Fix firmware load work teardown
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA arbiter client on registe
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started