MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooComme
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to el
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory
Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that
Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross S
Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component
Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables
A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an uppe
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) i
NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when enco
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsin
In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/ent
NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of a
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a
A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” pe
The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an
The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameter
E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote att
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer ove
NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-boun
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes
NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deseri
NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial
The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin
The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.
Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s
The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection v
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc
An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly acces
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in
libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (wr
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started