In the Linux kernel, the following vulnerability has been resolved: net: devmem: prevent net-iov / page mixing We shou
In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_netdev: Preserve RX queue depth on allocat
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: release template ct on non-IP pa
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: defer invalid log until af
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix sk_buff leak when the header
In the Linux kernel, the following vulnerability has been resolved: vxlan: do not arm the ageing timer on a device that
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: read virtqueues under worker locks C
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: avoid refilling the RX queue after te
In the Linux kernel, the following vulnerability has been resolved: tls: don't leave a full plaintext sk_msg ring unpus
In the Linux kernel, the following vulnerability has been resolved: tipc: read le->link under the node lock in tipc_nod
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Serialize accesses to the owner and mirro
In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix use-after-free in eventfs_remove_rec()
In the Linux kernel, the following vulnerability has been resolved: eventfs: Use children field for rcu head and add me
In the Linux kernel, the following vulnerability has been resolved: Revert "thermal/drivers/hwmon: Cleanup coding style
In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM board
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Use current_context for safe per-CPU b
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix Route Information option length validatio
In the Linux kernel, the following vulnerability has been resolved: fscrypt: use the mount idmap for the owner check in
In the Linux kernel, the following vulnerability has been resolved: sched/psi: Shut down rtpoll_timer in psi_cgroup_fre
In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate ho
In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assu
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix sk_redir use-after-free in send v
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to u
hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecti
NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows at
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.E
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader modu
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit wa
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle m
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Valida
Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain nul
Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable
SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoin
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() retur
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens witho
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-s
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce che
The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrator
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which auth
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to
Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS a
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay au
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are pr
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset re
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user upda
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated rem
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started