RiteCMS v3.1.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the parse_specia
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remot
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-e
A SQL injection vulnerability was found in the '/cts/admin/?page=zone' file of ITSourcecode COVID Tracking System Using
A Cross-site scripting (XSS) vulnerability in Create/Update Item(s) Module in Open Source Point of Sale v3.4.1 allows re
An issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates
The Portrait Dell Color Management application 3.3.8 for Dell monitors has Insecure Permissions,
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software v
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encry
A vulnerability in the application software of multiple Radiometer products may allow remote code execution and unauthor
A vulnerability exists in multiple Radiometer products that allow an attacker with physical access to the analyzer possi
Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj
ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replac
Fuji Electric Monitouch V-SFT-6 is vulnerable to an out-of-bounds write while processing a specially crafted project fi
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated
Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exp
Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap
SIPGO is a library for writing SIP services in the GO language. Starting in version 0.3.0 and prior to version 1.0.0-alp
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A
An out-of-bounds read vulnerability exists in the JPEGBITSCodec::InternalCode functionality of Grassroot DICOM 3.024. A
An out-of-bounds read vulnerability exists in the Overlay::GrabOverlayFromPixelData functionality of Grassroot DICOM 3.0
An out-of-bounds read vulnerability exists in the RLECodec::DecodeByStreams functionality of Grassroot DICOM 3.024. A sp
Expr is an expression language and expression evaluation for Go. Prior to version 1.17.7, several builtin functions in E
@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_find
systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` funct
nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.
Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce t
NVIDIA Resiliency Extension for Linux contains a vulnerability in the checkpointing core, where an attacker may cause a
NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predict
NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG files with embedded exter
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attacke
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site
In the Linux kernel, the following vulnerability has been resolved: page_pool: always add GFP_NOWARN for ATOMIC allocat
In the Linux kernel, the following vulnerability has been resolved: lan966x: Fix sleeping in atomic context The follow
In the Linux kernel, the following vulnerability has been resolved: io_uring/zctx: check chained notif contexts Send z
In the Linux kernel, the following vulnerability has been resolved: drm/msm: make sure last_fence is always updated Up
In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an is
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: lookup hci_conn on RX path on
In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel: punit_ipc: fix memory corrupti
In the Linux kernel, the following vulnerability has been resolved: net: sxgbe: fix potential NULL dereference in sxgbe
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: ensure vectored buffer node import is
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check NULL before accessing [WHAT
In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->
Exposure of Private Personal Information to an Unauthorized Actor vulnerability in RTI Connext Professional (Core Librar
In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespa
In the Linux kernel, the following vulnerability has been resolved: ext4: add i_data_sem protection in ext4_destroy_inl
In the Linux kernel, the following vulnerability has been resolved: rust_binder: fix race condition on death_list Rust
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started