In multiple locations, there is a possible way to delete media without the MANAGE_EXTERNAL_STORAGE permission due to an
In multiple functions of MediaProvider.java, there is a possible external storage write permission bypass due to a confu
In multiple functions of MediaProvider.java, there is a possible way to bypass the WRITE_EXTERNAL_STORAGE permission due
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a race condition. This
In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events du
In multiple locations, there is a possible lockscreen bypass due to a race condition. This could lead to local escalatio
In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive director
In UsageEvents of UsageEvents.java, there is a possible out of bounds write due to an incorrect bounds check. This could
In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind
The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (
Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be execute
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Creator
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, t
Memory corruption while using alignments for memory allocation.
An issue was discovered in /goform/WifiWpsStart in Tenda AC6V2.0 V15.03.06.23_multi. The index and mode are controllable
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio
Memory Corruption when processing invalid user address with nonstandard buffer address.
Memory Corruption when adding user-supplied data without checking available buffer space.
Memory Corruption while invoking IOCTL calls when concurrent access to shared buffer occurs.
Memory Corruption when accessing trusted execution environment without proper privilege check.
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
Memory Corruption while processing IOCTL calls when concurrent access to shared buffer occurs.
Memory Corruption when concurrent access to shared buffer occurs due to improper synchronization between assignment and
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
Memory Corruption when accessing a buffer after it has been freed while processing IOCTL calls.
Memory Corruption when concurrent access to shared buffer occurs during IOCTL calls.
Memory corruption while handling different IOCTL calls from the user-space simultaneously.
Memory Corruption when accessing buffers with invalid length during TA invocation.
Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin
Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow
Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /pl
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensiti
Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun
Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFi
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d
Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d
Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a
The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks.
The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client d
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (prox
In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started