In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Avoid double destroy of default endpoi
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning
In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: ensure data length is within supporte
In the Linux kernel, the following vulnerability has been resolved: ceph: fix race condition validating r_parent before
In the Linux kernel, the following vulnerability has been resolved: erofs: fix invalid algorithm for encoded extents T
In the Linux kernel, the following vulnerability has been resolved: ixgbe: fix incorrect map used in eee linkmode inco
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: add missing check for rx wcid e
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix linked list corruption Never leave
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds dynptr write in bpf_crypto_c
In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdi
In the Linux kernel, the following vulnerability has been resolved: i40e: fix IRQ freeing in i40e_vsi_request_irq_msix
In the Linux kernel, the following vulnerability has been resolved: net: dev_ioctl: take ops lock in hwtstamp lower pat
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: remove oem i2c adapter on finish
In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent p
In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is i
In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'com
In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX met
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued
In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Initialize the chan_stats array to z
Keysight Ixia Vision has an issue with hardcoded cryptographic material which may allow an attacker to intercept or dec
An Insecure Direct Object Reference (IDOR) in the /dashboard/notes endpoint of Syaqui Collegetivity v1.0.0 allows attack
Account Takeover in Corezoid 6.6.0 in the OAuth2 implementation via an open redirect in the redirect_uri parameter allow
LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The appli
NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause
There is a memory corruption vulnerability due to an out of bounds read in DefaultFontOptions() when using SymbolEditor
There is a memory corruption vulnerability due to an out of bounds write in XML_Serialize() when using SymbolEditor in N
An issue in finance.js v.4.1.0 allows a remote attacker to cause a denial of service via the seekZero() parameter.
Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper hand
Local privilege escalation due to insecure XPC service configuration. The following products are affected: Acronis True
An issue was discovered in Chipsalliance Rocket-Chip commit f517abbf41abb65cea37421d3559f9739efd00a9 (2025-01-29) allowi
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis True Image (
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an ou
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 143.0.3.
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143.
The Bei Fen – WordPress Backup Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,
The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and
The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQ
PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that d
The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1
The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with
Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package
go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it v
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.10
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary comma
libvips is a demand-driven, horizontally threaded image processing library. For versions 8.17.1 and below, when libvips
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started