The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these b
Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird
Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versi
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnera
A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL
In gnss driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escal
In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
In wlan AP driver, there is a possible out of bounds write due to an integer overflow. This could lead to remote (proxim
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affect
A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SI
A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SI
A cleartext transmission of sensitive information vulnerability in the affected products allows an unauthorized remote a
An low privileged remote attacker with an account for the Web-based management can change the system configuration to pe
An unauthenticated remote attacker can cause a Denial of Service by turning off the output of the UPS via Modbus command
Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of a
yt-grabber-tui is a terminal user interface application for downloading videos. In versions before 1.0-rc, the applicati
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Inj
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL In
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve re
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensit
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to esc
rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects M
In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_a
Authorization Bypass Through User-Controlled Key vulnerability in AKIN Software Computer Import Export Industry and Trad
Enterprise Cloud Database developed by Ragic has an Arbitrary File Upload vulnerability, allowing privileged remote atta
SOOP-CLM developed by PiExtract has a Hidden Functionality vulnerability, allowing privileged remote attackers to exploi
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSearch in 3DSwymer on Release 3DEXPERIENCE R2025x allows a
A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator
A stored Cross-site Scripting (XSS) vulnerability affecting Specification Management in ENOVIA Specification Manager fro
A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2025x allows an
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started