Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17):
Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELE
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cau
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS co
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a
A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTime
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highl
NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use ra
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed i
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A s
NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted dat
Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/
Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with pr
FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling.
FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trus
In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap,
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call
In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset
In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm
In the Linux kernel, the following vulnerability has been resolved: rust: arm64: set uwtable llvm module flag for CONFI
In the Linux kernel, the following vulnerability has been resolved: fhandle: fix UAF due to unlocked ->mnt_ns read in m
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_e
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector
A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to ac
MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree
MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass
MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin
@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-
DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
DVP80ES3 with Improper Resource Shutdown or Release vulnerability.
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started