In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: do not free existing class in q
In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tc
In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: j1939_xtp_rx_rts_session_active():
In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af
Microvirt MEMU Play 3.7.0 contains an unquoted service path vulnerability in the MEmusvc Windows service that allows loc
Magic Mouse 2 Utilities 2.20 contains an unquoted service path vulnerability in its Windows service configuration. Attac
KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local
Deep Instinct Windows Agent 1.2.24.0 contains an unquoted service path vulnerability in the DeepNetworkService that allo
HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers
The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploa
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored
The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin
C++ HTTP Server is an HTTP/1.1 server built to handle client connections and serve HTTP requests. Versions 1.0 and below
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Vers
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In v
Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.2
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend
An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pr
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with rendere
PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execut
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app con
Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSyst
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of the change_params.p
PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that
Nsauditor 3.2.2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriti
Managed Switch Port Mapping Tool 2.85.2 contains a denial of service vulnerability that allows attackers to crash the ap
AgataSoft PingMaster Pro 2.1 contains a denial of service vulnerability in the Trace Route feature that allows attackers
PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' parame
LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service running with LocalSystem p
Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allo
Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in u
dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to over
In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_wor
In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_a
In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to pa
In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply
In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not chang
In the Linux kernel, the following vulnerability has been resolved: nfsd: provide locking for v4_end_grace Writing to
In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correcti
In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: ensure worker is torn down When an IR
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started