XMedia Recode 3.4.8.6 contains a denial of service vulnerability that allows attackers to crash the application by loadi
ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by in
A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an
The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A path traversal vul
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulner
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vuln
Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient
An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestr
Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allo
A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f
When BIG-IP AFM or BIG-IP DDoS is provisioned, undisclosed traffic can cause TMM to terminate. Note: Software versions
Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all
In the Linux kernel, the following vulnerability has been resolved: smb: client: split cached_fid bitfields to avoid sh
In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use ctx->lock to protect struct v
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list x
In the Linux kernel, the following vulnerability has been resolved: sched/mmcid: Don't assume CID is CPU owned on mode
In the Linux kernel, the following vulnerability has been resolved: erofs: fix UAF issue for file-backed mounts w/ dire
In the Linux kernel, the following vulnerability has been resolved: xfs: fix UAF in xchk_btree_check_block_owner We ca
In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scat
In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc: fix use-after-free in driver_override_
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate sp before freeing associate
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_
In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - Fix out-of-bounds index in find_empty
Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-prov
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix use-after-free in iscsit_d
The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the
A vulnerability has been identified in Rexroth IndraWorks. This flaw allows an attacker to execute arbitrary code on the
A vulnerability has been identified in the UA.Testclient utility, which is included in Rexroth IndraWorks. All versions
A vulnerability has been identified in the OPC.Testclient utility, which is included in Rexroth IndraWorks. All versions
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou
NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code i
NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code inj
NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A
The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerable
The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Injec
The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl
The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started