In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe(
In the Linux kernel, the following vulnerability has been resolved: PCI: hv: Fix double ida_free in hv_pci_probe error
In the Linux kernel, the following vulnerability has been resolved: xsk: tighten UMEM headroom validation to account fo
In the Linux kernel, the following vulnerability has been resolved: xfrm: Wait for RCU readers during policy netns exit
In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: make hash table per que
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline data i_size during inode rea
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_write_end_i
In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace
The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2
A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no addition
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additio
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service w
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir f
Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1,
Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c
A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file
A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp
In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap
Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the T
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i
Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is
A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec
A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module
RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does no
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started