Memory corruption when passing parameters to the Trusted Virtual Machine during the handshake.
Horilla is a free and open source Human Resource Management System (HRMS). An authenticated Remote Code Execution (RCE)
NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data crea
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data crea
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an a
NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b
A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Disable works on hci_unregiste
A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att
Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att
A predictable seed in pseudo-random number generator vulnerability has been discovered in firmware version 3.60 of the C
The use of a broken or risky cryptographic algorithm was discovered in firmware version 3.60 of the Click Plus PLC. The
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, pote
Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL
Buffer overflow vulnerability in Tenda AC9 1.0 via the user supplied sys.vendor configuration value.
Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 in the sub_451754 function of the jhttpd service in the viav
A heap-buffer-overflow vulnerability exists in the tcpliveplay utility of the tcpreplay-4.5.1. When a crafted pcap file
Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.This issue affects
Free5gc 4.0.1 is vulnerable to Buffer Overflow. The AMF incorrectly validates the 5GS mobile identity, resulting in slic
A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malfor
Improper Input Validation vulnerability in TOTOLINK X6000R allows Flooding.This issue affects X6000R: through V9.4.0cu.1
Buffer Over-read, Off-by-one Error vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation,
A flaw was found in Libtiff. This vulnerability is a "write-what-where" condition, triggered when the library processes
Uncontrolled Search Path Element vulnerability in Salesforce Salesforce CLI on Windows allows Replace Trusted Executable
A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Type Confusion vulnerability. A maliciou
The huggingface/transformers library, versions prior to 4.53.0, is vulnerable to Regular Expression Denial of Service (R
A maliciously crafted HTML payload, when rendered by the Autodesk Fusion desktop application, can trigger a Stored Cross
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft
A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown fu
A security flaw has been discovered in Campcodes Gym Management System 1.0. Impacted is an unknown function of the file
In the Linux kernel, the following vulnerability has been resolved: fuse: Block access to folio overlimit syz reported
In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(
In the Linux kernel, the following vulnerability has been resolved: drm/mediatek: fix potential OF node use-after-free
In the Linux kernel, the following vulnerability has been resolved: kernfs: Fix UAF in polling when open file is releas
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: fix use-after-free in state_show()
In the Linux kernel, the following vulnerability has been resolved: can: xilinx_can: xcan_write_frame(): fix use-after-
In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev h
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Remove improper idxd_free The cal
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix double free in idxd_setup_wqs(
In the Linux kernel, the following vulnerability has been resolved: dmaengine: ti: edma: Fix memory allocation size for
In the Linux kernel, the following vulnerability has been resolved: erofs: fix runtime warning on truncate_folio_batch_
A flaw has been found in Reservation Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown f
A vulnerability was detected in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /ad
A security vulnerability has been detected in code-projects Online Bidding System 1.0. This impacts an unknown function
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package
A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function sub_45BB10 of the file /g
A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function o
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started