In the Linux kernel, the following vulnerability has been resolved: mm/slub: reset KASAN tag in defer_free() before acc
In the Linux kernel, the following vulnerability has been resolved: MIPS: ftrace: Fix memory corruption when kernel is
External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a
The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions
The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and
The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to Sto
The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request
The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu
Double free vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affe
Multi-thread race condition vulnerability in the video framework module. Impact: Successful exploitation of this vulnera
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnerab
Multi-thread race condition vulnerability in the card framework module. Impact: Successful exploitation of this vulnera
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-
WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by mani
Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbit
Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to
Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows attac
Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra
Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows loca
e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to overrid
CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with
WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload mal
Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attack
TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable fi
Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows
Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows
BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows lo
Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execu
Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with
WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra
Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local a
VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrar
ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows loca
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server
PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers t
EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. A
ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows
Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts thr
e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upl
Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute
Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started