Memory corruption while processing multiple IOCTL command for escape operations.
Memory corruption while processing IOCTL calls for escape operations.
Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Sec
Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat
Memory Corruption when processing fastboot commands to set display mode.
Memory corruption while processing fastboot commands with improperly formatted input.
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
Memory corruption while processing fastboot commands with invalid input.
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bo
Memory corruption while processing fastboot OEM commands.
Memory Corruption when processing display command line information due to improper initialization of a variable.
Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initi
Memory Corruption when processing device identifier strings that exceed the expected maximum length.
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
Dräger Infinity Explorer C700 contains a privilege escalation vulnerability that allows attackers to break out of kiosk
Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by
Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote at
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to lo
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/formF
A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /gofor
A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unk
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to loc
In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to mi
In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged
In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to cert
In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of priv
In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell u
In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missi
In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to mislea
In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app
In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input va
In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This coul
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl
In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic
In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. Thi
In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalat
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in
In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass
In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to
In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead
In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when
In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in th
In multiple locations, there is a possible way to reveal images across users due to improper input validation. This coul
WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary S
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started