Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load m
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, r
Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, pote
Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in
Missing authorization in AMD RomArmor could allow an attacker to bypass ROMArmor protections during system resume from a
Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary m
Improper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents
Type confusion in the ASP could allow an attacker to pass a malformed argument to the Reliability, Availability, and Ser
A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_resp
A vulnerability has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file
A security vulnerability has been detected in Campcodes Grocery Sales and Inventory System 1.0. Impacted is an unknown f
A weakness has been identified in Campcodes Grocery Sales and Inventory System 1.0. This issue affects some unknown proc
The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c
The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a def
The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrar
ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, l
Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecur
Insufficient bounds checking in AMD TEE (Trusted Execution Environment) could allow an attacker with a compromised users
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerab
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix unbuffered write error handling If all
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix refcount leak causing resource not relea
In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header befo
In the Linux kernel, the following vulnerability has been resolved: open_tree_attr: do not allow id-mapping changes wit
In the Linux kernel, the following vulnerability has been resolved: media: usbtv: Lock resolution while streaming When
In the Linux kernel, the following vulnerability has been resolved: media: ivsc: Fix crash at shutdown due to missing m
In the Linux kernel, the following vulnerability has been resolved: media: venus: Add a check for packet size after rea
In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix stack protector issue in send_i
In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version che
In the Linux kernel, the following vulnerability has been resolved: io_uring/futex: ensure io_futex_wait() cleans up pr
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix a race when updating an existing write Af
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: tas2781: Fix wrong reference of tasdevic
In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Fix SCCB present check Tracing code cal
In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() h
In the Linux kernel, the following vulnerability has been resolved: ftrace: Also allocate and copy hash for reading of
In the Linux kernel, the following vulnerability has been resolved: iio: light: as73211: Ensure buffer holes are zeroed
In the Linux kernel, the following vulnerability has been resolved: comedi: Make insn_rw_emulate_bits() do insn->n samp
In the Linux kernel, the following vulnerability has been resolved: comedi: pcl726: Prevent invalid irq number The rep
In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser->buffer when trace_
In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_
In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix backlog accounting in qdisc_dequeue_
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: Fix PHY address mask in MDI
In the Linux kernel, the following vulnerability has been resolved: gve: prevent ethtool ops after shutdown A crash ca
In the Linux kernel, the following vulnerability has been resolved: s390/mm: Do not map lowcore with identity mapping
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix vm_bind_ioctl double free bug If the a
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started