Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engag
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2
AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate p
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tamperin
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53,
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.4
Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability t
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con
Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the con
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul
Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the conte
Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul
Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result i
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privilege
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged
Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vu
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support i
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A s
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overf
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource cons
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedco
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rule
A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's deco
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature ov
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a ne
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started