In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Inc
In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activ
In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disa
In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the
pgAdmin <= 9.7 is affected by a Cross-Origin Opener Policy (COOP) vulnerability. This vulnerability allows an attacker
In the Linux kernel, the following vulnerability has been resolved: io_uring/net: commit partial buffers on retry Ring
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descrip
In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix UAF in export_dmabuf() As soon as
In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A c
In the Linux kernel, the following vulnerability has been resolved: net: kcm: Fix race condition in kcm_unattach() syz
In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() Th
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds in hfsplus_bnode_re
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni
In the Linux kernel, the following vulnerability has been resolved: gfs2: Validate i_depth for exhash directories A fu
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The lengt
In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthre
In the Linux kernel, the following vulnerability has been resolved: drm/xe: Make dma-fences compliant with the safe acc
In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register
In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe(
In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG
In the Linux kernel, the following vulnerability has been resolved: iommufd: Prevent ALIGN() overflow When allocating
In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syz
In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imag
In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregis
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in u
In the Linux kernel, the following vulnerability has been resolved: media: venus: Fix OOB read due to missing payload b
NVIDIA DOCA contains a vulnerability in the collectx-dpeserver Debian package for arm64 that could allow an attacker wit
NVIDIA DOCA contains a vulnerability in the collectx-clxapidev Debian package that could allow an actor with low privile
NVIDIA BlueField contains a vulnerability in the management interface, where an attacker with local access could cause i
An authenticated SQL injection vulnerability in VX Guestbook 1.07 allows attackers with admin access to inject malicious
It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing a
Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applicat
A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the
A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_415
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown f
A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown
The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v
The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on
The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22
The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE
The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validatio
Markdownify is a Model Context Protocol server for converting almost anything to Markdown. Versions below 0.0.2 contain
Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or over
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan
In draw_surface_image() of abl/android/lib/draw/draw.c, there is a possible out of bounds write due to a heap buffer ove
In ConvertReductionOp of darwinn_mlir_converter_aidl.cc, there is a possible out of bounds write due to a heap buffer ov
In gxp_mapping_create of gxp_mapping.c, there is a possible privilege escalation due to a logic error in the code. This
In lwis_io_buffer_write, there is a possible OOB read/write due to improper input validation. This could lead to local e
WLAN in Android before 2025-09-05 on Google Pixel devices allows elevation of privilege, aka A-396462223.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started