TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary
A CSV Formula Injection vulnerability in TrueConf Server v5.5.2.10813 allows a normal user to inject malicious spreadshe
A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference fun
A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthum
A weakness has been identified in BiggiDroid Simple PHP CMS 1.0. Affected is an unknown function of the file /admin/logi
A NULL pointer dereference in the src/path.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Servi
A divide-by-zero in the encryption/decryption routines of GNU Recutils v1.9 allows attackers to cause a Denial of Servic
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appointify Appoint
A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRo
A vulnerability was identified in Edimax BR-6208AC 1.02/1.03. Affected is the function formStaDrvSetup of the file /gofo
nixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.
A vulnerability has been found in Tenda M3 1.0.0.13(4903). The impacted element is an unknown function of the file /gofo
A flaw has been found in Tenda M3 1.0.0.13(4903). The affected element is the function formSetRemoteDhcpForAp of the fil
In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Free IRQs before removing
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix out-of-bounds read When preparin
In the Linux kernel, the following vulnerability has been resolved: net/smc: use smc_lgr_list.lock to protect smc_lgr_l
In the Linux kernel, the following vulnerability has been resolved: dm flakey: don't corrupt the zero page When we nee
In the Linux kernel, the following vulnerability has been resolved: scsi: message: mptlan: Fix use after free bug in mp
In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: Create card with device-managed snd_d
In the Linux kernel, the following vulnerability has been resolved: net: tls: avoid hanging tasks on the tx_lock syzbo
In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_perf_event_output T
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dvm: Fix memcpy: detected field-span
In the Linux kernel, the following vulnerability has been resolved: iomap: Fix possible overflow condition in iomap_wri
In the Linux kernel, the following vulnerability has been resolved: media: av7110: prevent underflow in write_ts_to_dec
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Don't clone flow post action attributes
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Don't leak a resource on eviction error O
In the Linux kernel, the following vulnerability has been resolved: ksmbd: avoid out of bounds access in decode_preauth
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix table blob use-after-free
In the Linux kernel, the following vulnerability has been resolved: mlx5: fix skb leak while fifo resync and push Duri
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix missing mrioc->evtack_cmds initia
In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix tags leak when shrink nr_hw_queues Alt
In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix oops for port->pm on uart_change_
In the Linux kernel, the following vulnerability has been resolved: Revert "IB/isert: Fix incorrect release of isert co
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: TC, Fix using eswitch mapping in nic mod
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix potential user-after-free Th
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Avoid use-after-free in dbg fo
In the Linux kernel, the following vulnerability has been resolved: HID: uclogic: Correct devm device reference for hid
In the Linux kernel, the following vulnerability has been resolved: net/sched: flower: fix filter idr initialization T
In the Linux kernel, the following vulnerability has been resolved: drm/i915: fix race condition UAF in i915_perf_add_c
In the Linux kernel, the following vulnerability has been resolved: RDMA/efa: Fix wrong resources deallocation order W
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always release netdev hooks f
In the Linux kernel, the following vulnerability has been resolved: tty: fix out-of-bounds access in tty_driver_lookup_
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: remove block_cb from driver_lis
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential corruption when moving a direct
In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignmen
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to check readonly condition correctly Wi
In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_event_output We rec
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx4: Prevent shift wrapping in set_user_sq_si
In the Linux kernel, the following vulnerability has been resolved: igc: Fix Kernel Panic during ndo_tx_timeout callbac
In the Linux kernel, the following vulnerability has been resolved: zsmalloc: move LRU update from zs_map_object() to z
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started