Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a ne
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer all
Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.
Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges o
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification
Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p
Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na
An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths withi
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump file
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 thr
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigge
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-o
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The co
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of p
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by mea
A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attacke
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauth
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that al
Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via t
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of
A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the
A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file
A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/S
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri
In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSC
On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the
A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFil
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) compo
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) comp
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started