Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the con
CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary
CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut
Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev
Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routin
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi
linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the pack
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co
After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context
Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context
Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in th
Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co
ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature byp
ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A l
ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerabi
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context
After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c
Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary c
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co
Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in
Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c
Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i
NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex
NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-
NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a
NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful
NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploi
NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A succ
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization
NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker co
Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitra
Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the render
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 al
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started