A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown fu
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of t
Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-all
RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type
libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses
FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions
Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user
The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer
The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the P
Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va
The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin
The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace,
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of servi
A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arb
A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to t
The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAu
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints
An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsSer
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas
Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce
Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the pa
Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoin
Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a publi
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDef
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter">
Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege esc
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS)
An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of S
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP fronten
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an a
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling functio
In the Linux kernel, the following vulnerability has been resolved: f2fs: protect extension_list reading with sb_lock i
In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix NTMP DMA use-after-free issue The
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: free channels on probe error
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channe
In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before strea
In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux dev
In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after s
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refco
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages mo
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started