OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC drive
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0
A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive an
prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status pol
prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate che
prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attacker
Storage credentials are hardcoded in the mobile app and device firmware. These credentials do not adequately limit end u
Hirschmann Industrial HiVision version 08.1.03 prior to 08.1.04 and 08.2.00 contains a vulnerability in the execution of
Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet
Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak ps
Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity
Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin
In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/
In the Linux kernel, the following vulnerability has been resolved: HID: bpf: prevent buffer overflow in hid_hw_request
In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchr
In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages
In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async e
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload l
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option C
In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration
immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich applica
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided c
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Open-code GGTT MMIO access protection GGTT
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: Fix possible UAF This fixes the f
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_unreg
In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PC
In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: fix use-after-free in ctnetli
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix Content-Length u32
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decod
In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in mana_hwc_destroy_c
In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: Fix memory leak in XDP_DROP
In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_he
In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: Fix double-free in teql_master_xmi
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes b
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes b
In the Linux kernel, the following vulnerability has been resolved: igc: fix page fault in XDP TX timestamps handling
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: always free skb on ieee80211_tx_pre
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN upda
In the Linux kernel, the following vulnerability has been resolved: net: shaper: protect late read accesses to the hier
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: serialize lock/unlock against other N
In the Linux kernel, the following vulnerability has been resolved: mshv: Fix use-after-free in mshv_map_user_memory er
In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Fix crash in iommu_sva_unbind_device()
An issue was discovered in Biztalk360 before 11.5. Because of mishandling of user-provided input in an upload mechanism,
An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started