An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s
MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h
A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouver
A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.
A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert La
The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set
The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv
Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL
Use of insufficiently random value of secretKey in Smart Switch prior to version 3.7.68.6 allows adjacent attackers to a
The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15
Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen
Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta all
Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr
Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may
Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor'
CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.
Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con
Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.
Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted pro
A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which ma
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380,
NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path eleme
An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. T
An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results
An issue was discovered in Samsung Mobile Processor Exynos 2400, 1580, 2500. A race condition in the HTS driver results
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is a NULL Pointer Derefe
An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 12
An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 13
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
A lack of authorisation vulnerability has been detected in CanalDenuncia.app. This vulnerability allows an attacker to a
An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started