A local low privileged attacker can bypass the authentication of the Device Manager user interface, allowing them to per
A low privileged remote attacker can execute arbitrary code by sending specially crafted calls to the web service of the
Missing Release of Memory after Effective Lifetime vulnerability in Is-Daouda is-Engine.This issue affects is-Engine: be
Out-of-bounds Write vulnerability in gerstrong Commander-Genius.This issue affects Commander-Genius: before Release refs
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization che
Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability.
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* ac
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10
beat-access for Windows version 3.0.3 and prior contains an issue with the DLL search path, which may lead to insecurely
ASDA-Soft Stack-based Buffer Overflow Vulnerability
MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vu
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exi
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113. Affected is the function Page_Loa
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_ma
Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.24.0, when running Skipper as an
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to vers
SQL Injection vulnerability in the Structure for Admin authenticated user
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-ser
A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of th
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid no
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to clone PersistentVolu
Command injection vulnerability was found in the admin interface component of TP-Link Archer MR600 v5 firmware, allowing
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwords to be changed thr
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorization flaw in the user
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a secu
IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute a
Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local
PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attac
MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attacke
An issue in continuous.software aangine v.2025.2 allows a remote attacker to obtain sensitive information via the excel-
IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLI
A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Releas
The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated re
A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown f
The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting
A flaw has been found in Tenda AC23 16.03.07.52. This impacts an unknown function of the file /goform/WifiExtraSet. This
A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacte
In the Linux kernel, the following vulnerability has been resolved: net: octeon_ep_vf: fix free_irq dev_id mismatch in
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: remove call_control in inactive cont
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix use-after-free in inet6_addr_del(). syzb
In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_de
In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tn
In the Linux kernel, the following vulnerability has been resolved: macvlan: fix possible UAF in macvlan_forward_source
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started