Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitr
Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated att
Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to exe
Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execut
Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute a
Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execut
Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execu
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace perio
In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device
In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is c
AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-pr
Chromacam 4.0.3.0 contains an unquoted service path vulnerability in the PsyFrameGrabberService that allows local attack
Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attacke
Brother SAPSprint 7.60 contains an unquoted service path vulnerability in the SAPSprint service binary that allows local
Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppS
Winstep 18.06.0096 contains an unquoted service path vulnerability in the Winstep Xtreme Service that allows local attac
Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows loca
RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows lo
TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows lo
Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attack
Matrix42 Remote Control Host 3.20.0031 contains an unquoted service path vulnerability in the FastViewerRemoteService an
AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYS
Wise Care 365 4.27 and Wise Disk Cleaner 9.29 contain unquoted service path vulnerabilities in the WiseBootAssistant and
NetDrive 2.6.12 contains an unquoted service path vulnerability in the Netdrive2_Service_Netdrive2 service that allows l
Windows Firewall Control 4.8.6.0 contains an unquoted service path vulnerability that allows local attackers to escalate
Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater serv
Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code w
Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that
Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code
Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer servi
Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attack
Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some
There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may
Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul
Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t
Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileg
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor
SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w
PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the t
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthor
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started