A security vulnerability has been detected in Wavlink WL-WN578W2 221110. This affects the function sub_404850 of the fil
The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici
A stack overflow in the FTP service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to cause a Denial of
An issue in Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to arbitrarily overwrite files via supplying a
Incorrect access control in the web service of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to download
Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA
A vulnerability was determined in Wavlink WL-WN578W2 221110. This affects the function sub_401C5C of the file firewall.c
A vulnerability was found in Wavlink WL-WN578W2 221110. The impacted element is the function sub_409184 of the file /wiz
OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK B
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code vi
An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via the default password
An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the default password. NOTE: t
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix the setting of capabilities when automount
In the Linux kernel, the following vulnerability has been resolved: xfrm: Duplicate SPI Handling The issue originates
In the Linux kernel, the following vulnerability has been resolved: net: lapbether: ignore ops-locked netdevs Syzkalle
In the Linux kernel, the following vulnerability has been resolved: io_uring/memmap: cast nr_pages to size_t before shi
In the Linux kernel, the following vulnerability has been resolved: dm: Always split write BIOs to zoned device limits
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, sp
A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visibl
Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitra
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitra
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak
The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18
An issue has been discovered in GitLab CE/EE affecting all versions from 7.12 before 18.1.6, 18.2 before 18.2.6, and 18.
The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.
The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all vers
Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to ver
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network
IBM Fusion 2.2.0 through 2.10.1, IBM Fusion HCI 2.2.0 through 2.10.0, and IBM Fusion HCI for watsonx 2.8.2 through 2.10.
A potential vulnerability was reported in the Lenovo Wallpaper Client that could allow arbitrary code execution under ce
A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that cou
An internal product security audit of Lenovo XClarity Orchestrator (LXCO) discovered the below vulnerability: An attack
A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drive
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2
In the Linux kernel, the following vulnerability has been resolved: dm: dm-crypt: Do not partially accept write BIOs wi
In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Detect events pointing to unexpecte
In the Linux kernel, the following vulnerability has been resolved: crypto: x86/aegis - Add missing error checks The s
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXU
In the Linux kernel, the following vulnerability has been resolved: soc: qcom: mdt_loader: Ensure we don't read past th
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7173: fix channels index for syscalib_m
In the Linux kernel, the following vulnerability has been resolved: drm/hisilicon/hibmc: fix irq_request()'s irq name v
In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix configfs group list head handlin
In the Linux kernel, the following vulnerability has been resolved: sched/ext: Fix invalid task state transitions on cl
In the Linux kernel, the following vulnerability has been resolved: btrfs: subpage: keep TOWRITE tag until folio is cle
In the Linux kernel, the following vulnerability has been resolved: mm/debug_vm_pgtable: clear page table entries at de
In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on device
In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN whe
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started