A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade
Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities
PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")
The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability
A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Af
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low p
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with l
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D
Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J
Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES
Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri
Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules
In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link
In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_
In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc i
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of dev
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder i
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node()
In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading rea
In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_s
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption
In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as globa
In the Linux kernel, the following vulnerability has been resolved: power: supply: pm8916_lbc: Fix use-after-free for e
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized buffer when receiving POST r
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 uses a static authentication nonce that does not change
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation whe
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backu
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Ba
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started