FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and A
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decod
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes
libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that a
libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S
libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ss
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src
sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t
sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P
sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo
sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at
Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administ
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs()
In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_
In the Linux kernel, the following vulnerability has been resolved: fpga: region: fix use-after-free in child_regions_w
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when queryi
In the Linux kernel, the following vulnerability has been resolved: power: reset: linkstation-poweroff: fix use-after-f
In the Linux kernel, the following vulnerability has been resolved: fbdev: modedb: fix a possible UAF in fb_find_mode()
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds c
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: net2280: Fix double free in probe erro
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: delete tried region in regi
In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use
In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in d
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() in
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: add bounds check to cgx_speed_mb
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix double free in rvu_rep_rsrc_init(
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: consume only present negotiated TTL
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on A
In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup fa
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_i
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_g
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ Duri
In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access
In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-ver
The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are
Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the
It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2
Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s
NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser
Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_
Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started