A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of
A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file
CYRISMA Sensor before 444 for Windows has an Insecure Folder and File Permissions vulnerability. A low-privileged user c
A DLL hijacking vulnerability in CYRISMA Agent before 444 allows local users to escalate privileges and execute arbitrar
An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only
Substance3D - Stager versions 3.1.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft
Greenshot is an open source Windows screenshot utility. Greenshot 1.3.300 and earlier deserializes attacker-controlled d
Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsuppo
In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: dccp: copy entire header to s
In the Linux kernel, the following vulnerability has been resolved: pstore/ram: Check start of empty przs during init
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Wait for io return on terminate rpor
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: drop short frames While tech
In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info
In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: Free resources after unregistering them
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Fix SKB corruption in REO destination
In the Linux kernel, the following vulnerability has been resolved: fbdev/ep93xx-fb: Do not assign to struct fb_info.de
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix use-after-free of nilfs_root in dirtyin
In the Linux kernel, the following vulnerability has been resolved: net: fec: Better handle pm_runtime_get() failing in
In the Linux kernel, the following vulnerability has been resolved: rbd: avoid use-after-free in do_rbd_add() when rbd_
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free Fix potential
In the Linux kernel, the following vulnerability has been resolved: cifs: fix oops during encryption When running xfst
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: avoid hci_dev_test_and_set_flag() in mgm
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerabi
A maliciously crafted PDF file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerab
The mcp-database-server (MCP Server) 1.1.0 and earlier, as distributed via the npm package @executeautomation/database-s
code-projects Computer Laboratory System 1.0 has a file upload vulnerability. Staff can upload malicious files by upload
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local use
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web
In Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, w
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph par
In the Linux kernel, the following vulnerability has been resolved: efi: stmm: Fix incorrect buffer allocation method
In the Linux kernel, the following vulnerability has been resolved: xfs: do not propagate ENODATA disk errors into xatt
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issu
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the sys
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configu
In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Prevent arbitrary write in atmtcp_recv
In the Linux kernel, the following vulnerability has been resolved: net: rose: include node references in rose_neigh re
In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The '
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rena
In the Linux kernel, the following vulnerability has been resolved: HID: asus: fix UAF via HID_CLAIMED_INPUT validation
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that
In the Linux kernel, the following vulnerability has been resolved: perf: Avoid undefined behavior from stopping/starti
In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-thc: Fix incorrect pointe
In the Linux kernel, the following vulnerability has been resolved: efivarfs: Fix slab-out-of-bounds in efivarfs_d_comp
In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: fix stack overrun when loading vlenb
In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix memory corruption when FW resources ch
In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quicki2c: Fix ACPI dsd IC
In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix slab out-of-bounds access in m
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started