Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.
wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increme
wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never incre
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregate
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the P
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allow
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic
An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Servic
An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of
vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMed
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a C
SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunction
SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experim
gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-cont
gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule n
gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-
gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when de
gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as te
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fai
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authentic
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint tha
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpo
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoi
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowin
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agen
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which
None None None No publicly available exploits are known.
An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenti
An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresse
In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: prevent read-only mappings from becom
In the Linux kernel, the following vulnerability has been resolved: of: reserved_mem: prevent OOB when too many dynamic
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: validate individual TWT params befo
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: ensure no dangling hcon references
In the Linux kernel, the following vulnerability has been resolved: iomap: add a separate bio_set for iomap_split_ioend
In the Linux kernel, the following vulnerability has been resolved: mm/percpu-km: fix bitmap overflow and accounting in
In the Linux kernel, the following vulnerability has been resolved: sctp: validate Adaptation Indication parameter leng
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd
In the Linux kernel, the following vulnerability has been resolved: io_uring: preserve task restrictions across exec P
In the Linux kernel, the following vulnerability has been resolved: spi: spi-qpic-snand: write the feature value before
In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Fix undersized format-check buffer fmt_
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification wi
In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): i
In the Linux kernel, the following vulnerability has been resolved: can: softing: fw_parse(): validate firmware record
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix guest_memory_dirty bitfield clobber
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: validate external BO copy bounds for bo
In the Linux kernel, the following vulnerability has been resolved: hwmon: (ltc4282) Fix reading the minimum alarm volt
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started