Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers to access sensitive i
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers to access sensitive
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via th
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology Bee
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attack
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-139
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memo
In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload
In the Linux kernel, the following vulnerability has been resolved: s390/ctcm: Fix double-kfree The function 'mpc_rcvd
In the Linux kernel, the following vulnerability has been resolved: devlink: rate: Unset parent pointer in devl_rate_no
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq
In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: make sure the cdev fd is still active b
In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if alread
In the Linux kernel, the following vulnerability has been resolved: nios2: ensure that memblock.current_limit is set wh
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in __hfsplus_
In the Linux kernel, the following vulnerability has been resolved: hfs: fix KMSAN uninit-value issue in hfs_find_set_z
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_p
In the Linux kernel, the following vulnerability has been resolved: erofs: fix crafted invalid cases for encoded extent
In the Linux kernel, the following vulnerability has been resolved: sctp: avoid NULL dereference when chunk data buffer
In the Linux kernel, the following vulnerability has been resolved: ocfs2: clear extent cache after moving/defragmentin
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure/plugins/plugin/uplo
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerabil
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the middlewares included in
In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: don't rely on user vaddr alignment
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages.
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2
In the Linux kernel, the following vulnerability has been resolved: xfrm: delete x->tunnel as we delete x The ipcomp f
In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge().
The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted b
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, w
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows
A heap buffer overflow in compiler.c and compiler.h in Pepper language 0.1.1commit 961a5d9988c5986d563310275adad3fd181b2
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path.
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exc
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDe
WebPros Plesk before 18.0.73.5 and 18.0.74 before 18.0.74.2 on Linux allows remote authenticated users to execute arbitr
Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generati
An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200. Unnecessary registration of a hardwa
GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and
In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an u
In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to
A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerabil
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerabl
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started