Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to 0.16.2, Frigate'
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSe
A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phon
Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered
When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microk
When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the
When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to
A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalat
A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with el
A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment t
When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resour
When a per-request policy is configured on a BIG-IP APM portal access virtual server, undisclosed traffic can cause the
A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administ
A vulnerability exists in F5OS-A and F5OS-C systems that may allow an authenticated attacker with local access to escala
Undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. This issue may occur when a Datagr
When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for th
When Diffie-Hellman (DH) group Elliptic Curve Cryptography (ECC) Brainpool curves are configured in an SSL profile's Cip
When DNS cache is configured on a BIG-IP or BIG-IP Next CNF virtual server, undisclosed DNS queries can cause an increas
When the Allowed IP Addresses feature is configured on the F5OS-C partition control plane, undisclosed traffic can cause
A vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authentica
When a BIG-IP AFM denial-of-service (DoS) protection profile is configured on a virtual server, undisclosed requests can
When HTTP/2 Ingress is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.
When the database variable tm.tcpudptxchecksum is configured as non-default value Software-only on a BIG-IP system, undi
When the BIG-IP Advanced WAF and ASM security policy and a server-side HTTP/2 profile are configured on a virtual server
When BIG-IP SSL Orchestrator explicit forward proxy is configured on a virtual server and the proxy connect feature is e
When a BIG-IP Advanced WAF or BIG-IP ASM Security Policy is configured with a JSON content profile that has a malformed
When a BIG-IP APM OAuth access profile (Resource Server or Resource Client) is configured on a virtual server, undisclos
When a classification profile is configured on a virtual server without an HTTP or HTTP/2 profile, undisclosed requests
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by
When a virtual server, network address translation (NAT) object, or secure network address translation (SNAT) object use
When an iRule using an ILX::call command is configured on a virtual server, undisclosed traffic can cause the Traffic Ma
When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with
When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an
When BIG-IP SSL Orchestrator is enabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to termi
The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all
The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an
The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat
The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi
The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin
The WPBifröst – Instant Passwordless Temporary Login Links plugin for WordPress is vulnerable to Privilege Escalation du
The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account ta
The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered b
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_ki
In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length chec
In the Linux kernel, the following vulnerability has been resolved: media: tuner: xc5000: Fix use-after-free in xc5000_
In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot
In the Linux kernel, the following vulnerability has been resolved: bpf: Check the helper function is valid in get_help
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: populate ndo_change_mtu() to preve
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started