JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140
Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.3
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed
NULL Pointer Dereference vulnerability in ravynsoft ravynos.This issue affects ravynos: through 0.5.2.
An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The c
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a
The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip
A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an
The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back
The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param
Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P
SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versio
In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-compress: Reposition and add pcm_mutex I
In the Linux kernel, the following vulnerability has been resolved: hfs: fix missing hfs_bnode_get() in __hfs_bnode_cre
In the Linux kernel, the following vulnerability has been resolved: dm: don't attempt to queue IO under RCU protection
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: Drop aux devices together with DP contr
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on direct node in trun
In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Don't leak a resource on swapout move erro
In the Linux kernel, the following vulnerability has been resolved: f2fs: synchronize atomic write aborts To fix a rac
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix skb refcnt race after locking cha
In the Linux kernel, the following vulnerability has been resolved: f2fs: flush inode if atomic file is aborted Let's
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Avoid use-after-free in dbg fo
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_disco
In the Linux kernel, the following vulnerability has been resolved: netlink: annotate lockless accesses to nlk->max_rec
In the Linux kernel, the following vulnerability has been resolved: block/rq_qos: protect rq_qos apis with a new lock
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Ignore frags from uninitialized peer
In the Linux kernel, the following vulnerability has been resolved: ipmi: fix use after free in _ipmi_destroy_user() T
In the Linux kernel, the following vulnerability has been resolved: net: rds: don't hold sock lock when cancelling work
In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in ext4_orphan_cleanup I
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix "kernel NULL pointer dereference" err
In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock due to mbcache entry corruption
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix failed to find the peer with peer
A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of th
In the Linux kernel, the following vulnerability has been resolved: amdgpu: validate offset_in_bo of drm_amdgpu_gem_va
In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_c
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix potential kgd_mem UAFs kgd_mem poi
In the Linux kernel, the following vulnerability has been resolved: blk-mq: release crypto keyslot before reporting I/O
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: populate subvp cmd info only for t
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free bug of nilfs_root in nil
In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_enclosure_
In the Linux kernel, the following vulnerability has been resolved: ubi: Fix use-after-free when volume resizing failed
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: Use ktime_t rather than int when dealin
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started