In the Linux kernel, the following vulnerability has been resolved: iommufd: IOMMUFD_DESTROY should not increase the re
In the Linux kernel, the following vulnerability has been resolved: bpf: Zeroing allocated object from slab in bpf memo
In the Linux kernel, the following vulnerability has been resolved: mt76: mt7921: don't assume adequate headroom for SD
In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in tcp_write_timer_handler(
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Clean up integer overflow checking in m
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Clear nfc_target before being used Fix
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference state management for synchronous
Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can in
n8n is an open source workflow automation platform. Versions 0.123.1 through 1.119.1 do not have adequate protections to
Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary te
The Litmus platform uses JWT for authentication and authorization, but the secret being used for signing the JWT is only
In multiple locations of UsbDataAdvancedProtectionHook.java, there is a possible way to access USB data when the screen
In preparePackage of InstallPackageHelper.java, there is a possible way for an app to appear hidden upon installation wi
A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create
Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute app
HummerRisk thru v1.5.0 is using a vulnerable Snakeyaml component, allowing attackers with normal user privileges to hit
In DefaultTransitionHandler.java, there is a possible way to unknowingly grant permissions to an app due to a tapjacking
In __pkvm_load_tracing of trace.c, there is a possible out-of-bounds write due to improper input validation. This could
In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could l
In setDisplayName of AssociationRequest.java, there is a possible way to cause CDM associations to persist after the use
In findAvailRecognizer of VoiceInteractionManagerService.java, there is a possible way to become the default speech reco
In validateIconUserBoundary of PrintManagerService.java, there is a possible cross-user image leak due to a confused dep
In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible way to launch an activity from the
In multiple functions of arm-smmu-v3.c, there is a possible out-of-bounds write due to improper input validation. This c
In init_pkvm_hyp_vcpu of pkvm.c, there is a possible out of bounds write due to improper input validation. This could le
In DefaultTransitionHandler.java, there is a possible way to enable a tapjacking attack due to a insecure default. This
In onSomePackagesChanged of VoiceInteractionManagerService.java, there is a possible way for a third party application's
In getComponentName of MediaButtonReceiverHolder.java, there is a possible desync in persistence due to resource exhaust
In setDefaultKey of DefaultPaymentSettings.java, there is a possible way for an application to set the main user's defau
In multiple functions of WifiScanModeActivity.java, there is a possible way to bypass a device config restriction due to
In multiple locations, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay a
In appendFrom of Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to lo
In onUidImportance of DisassociationProcessor.java, there is a possible way to retain companion application privileges a
In initDecoder of C2SoftDav1dDec.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could l
In multiple functions of HeaderPrivacyIconsController.kt, there is a possible way to grand permissions across user due
In startAlwaysOnVpn of Vpn.java, there is a possible way to disable always-on VPN due to a logic error in the code. This
In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to
In multiple functions of BaseBundle.java, there is a possible way to execute arbitrary code due to a logic error in the
In connectInternal of MediaBrowser.java, there is a possible way to access while in use permission while the app is in b
In multiple functions of CertInstaller.java, there is a possible way to install certificates due to a permissions bypass
In sendCommand of MediaSessionRecord.java, there is a possible way to launch the foreground service while the app is in
In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. Thi
In multiple locations, there is a possible bypass of user profile boundary with a forwarded intent due to improper input
In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the cod
In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escala
In multiple functions of NotificationStation.java, there is a possible cross-profile information disclosure due to a con
In grantAllowlistedPackagePermissions of SettingsSliceProvider.java, there is a possible way for a third party app to mo
In disassociate of DisassociationProcessor.java, there is a possible way for an app to continue reading notifications wh
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started