A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_
A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 route
A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmwa
A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.
A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F
A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv
A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv
Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthent
Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to
Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an
pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver
pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker t
The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,
The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundati
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefma
In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encod
In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To pr
In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace se
In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit
In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->
In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix PP_MAGIC_MASK to avoid crashing on s
In the Linux kernel, the following vulnerability has been resolved: ext4: avoid potential buffer over-read in parse_app
In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in
In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_dispositio
In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4
In the Linux kernel, the following vulnerability has been resolved: crypto: skcipher - Fix reqsize handling Commit afd
Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verific
A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead
An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used
A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown func
An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm
A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon
A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple thr
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP mes
A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admi
Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argume
Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is ex
Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and avai
An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS)
If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default
A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exp
A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malici
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started