Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Reso
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler`
Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local a
CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module
A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System
A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the
A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-a
Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the
Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_appl
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileg
SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processin
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns at
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows
SurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat
In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces
In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g
An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan
The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a wo
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu
The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe
Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User
A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Remove latent out-of-bounds access in IO
In the Linux kernel, the following vulnerability has been resolved: mm: fix __vm_normal_page() to handle missing suppor
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_ad
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: stop TX during firmware restart
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Disable AVIC IPI virtualization on Hygon
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check
In the Linux kernel, the following vulnerability has been resolved: iommu: Handle unmap error when iommu_debug is enabl
In the Linux kernel, the following vulnerability has been resolved: iommupt: Check for missing PAGE_SIZE in the pgsize_
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait F
In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix dma_buffer leak on bus acquire
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in compare_guid
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in proc_show_fi
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor d
In the Linux kernel, the following vulnerability has been resolved: smb: client: require net admin for CIFS SWN netlink
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Don't setup bogus iov_iter for silencing
In the Linux kernel, the following vulnerability has been resolved: ALSA: asihpi: Fix potential OOB array access at rea
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: validate Add Extended Advertising
In the Linux kernel, the following vulnerability has been resolved: net: devmem: reject dma-buf bind with non-page-alig
In the Linux kernel, the following vulnerability has been resolved: net: hsr: defer node table free until after RCU rea
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started