Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these b
Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed
Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fi
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F
Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Megatek Communicat
The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarc
The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarch
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vegagrup Software Vega Maste
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix kernel crash due to null io->bio We shou
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Return the firmware result upon destroyi
In the Linux kernel, the following vulnerability has been resolved: ext4: add bounds checking in get_max_inline_xattr_v
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Fix use-after-free KFENCE violation dur
In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt8183: Add back SSPM related clocks
In the Linux kernel, the following vulnerability has been resolved: net: ena: fix shift-out-of-bounds in exponential ba
In the Linux kernel, the following vulnerability has been resolved: ubi: ensure that VID header offset + VID header siz
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/disp: fix use-after-free in error handl
The issue was addressed with improved input validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its s
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 18.7 and iPadOS 18.7,
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8, macOS Tahoe 26
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be abl
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26, visionOS 26. A ma
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26. Processing a maliciously c
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma
The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write file
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26. An app may be able to b
This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26. Incoming FaceTime cal
The issue was addressed by adding additional logic. This issue is fixed in macOS Tahoe 26. An app may be able to overrid
SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows
A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio
FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Ad
FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of
A security flaw has been discovered in SourceCodester Online Student File Management System 1.0. The impacted element is
3DAlloy is a lightWeight 3D-viewer for MediaWiki. From 1.0 through 1.8, the <3d> parser tag and the {{#3d}} parser funct
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu fil
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 202
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker t
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix scheduling while atomic in decompression
In the Linux kernel, the following vulnerability has been resolved: VMCI: check context->notify_page after call to get_
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started