OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,
curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,
Memory Corruption when handling power management requests with improperly sized input/output buffers.
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware
Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
Memory Corruption when retrieving output buffer with insufficient size validation.
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
Cryptographic issue while copying data to a destination buffer without validating its size.
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
Memory corruption while processing a frame request from user.
Memory corruption while preprocessing IOCTL request in JPEG driver.
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that
A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEn
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod
Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco
GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli
GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store
GLPI is a Free Asset and IT Management Software package. From 0.60 to before 10.0.24, an authenticated technician user c
OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. Fo
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in Serv
A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /u
A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown f
A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown func
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th
A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown co
A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown fun
A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the compone
In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding reques
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_fram
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy va
In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix work re-schedule after cancel in xfrm_nat
A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component H
A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data
A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file
A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of
A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the
A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /gof
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started