In the Linux kernel, the following vulnerability has been resolved: qed: Don't collect too many protection override GRC
In the Linux kernel, the following vulnerability has been resolved: cnic: Fix use-after-free bugs in cnic_delete_task
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix use-after-free bugs in otx2_sync_
In the Linux kernel, the following vulnerability has been resolved: ksmbd: smbdirect: verify remaining_data_length resp
In the Linux kernel, the following vulnerability has been resolved: zram: fix slot write race condition Parallel concu
In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Fix memory corruption when using identi
In the Linux kernel, the following vulnerability has been resolved: ASoC: codec: sma1307: Fix memory corruption in sma1
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Set merge to zero early in af_alg_
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_neg
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa
MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi
Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained
Karapace is an open-source implementation of Kafka REST and Schema Registry. Versions 5.0.0 and 5.0.1 contain an authent
Cursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the wa
phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of e
Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code
An unquoted search path or element vulnerability has been reported to affect NetBak Replicator. If a local attacker gain
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
HCL MyXalytics: 6.6. is affected by Mass Assignment vulnerability. Mass Assignment occurs when user input is automatica
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun
Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI
Cursor is a code editor built for programming with AI. In versions 1.7 and below, automatic loading of project-specific
HCL MyXalytics product is affected by Cross Site Scripting vulnerability in the web application. This can allow the exec
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user
An SQL injection vulnerability has been reported to affect Video Station. If a remote attacker gains a user account, the
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit
Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (R
An issue in DirectAdmin v1.680 allows unauthorized attackers to manipulate the page layout and replace the legitimate lo
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name
A TCL Smart TV running a vulnerable UPnP/DLNA MediaRenderer implementation is affected by a remote, unauthenticated Deni
Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loadi
The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic
The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due
The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to SQ
The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and
A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc
Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center
Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the sta
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta
Delta Electronics DIAScreen lacks proper validation of the user-supplied file. If a user opens a malicious file, an atta
Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerabil
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-S
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started