Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9
A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures. Version
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a
A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown functio
In multiple functions of DevicePolicyManagerService.java, there is a possible way to install unauthorized applications i
In onLastAccessedStackLoaded of ActionHandler.java , there is a possible way to bypass storage restrictions across apps
In afterKeyEventLockedInterruptable of InputDispatcher.cpp, there is a possible use after free. This could lead to local
In setMediaButtonReceiver of multiple files, there is a possible way to launch arbitrary activities from background due
In handleKeyGestureEvent of PhoneWindowManager.java, there is a possible lock screen bypass due to a logic error in the
In canForward of IntentForwarderActivity.java, there is a possible bypass of the cross profile intent filter most common
In hasInteractAcrossUsersFullPermission of AppInfoBase.java, there is a possible way to grant permissions to an app on t
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to grant notification access above t
In ParseTag of dng_ifd.cpp, there is a possible way to crash the image renderer due to a missing bounds check. This coul
In multiple locations, there is a possible way to mislead a user into approving an authentication prompt for one app whe
In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to
In multiple locations, there is a possible confused deputy due to Intent Redirect. This could lead to local escalation o
In finishTransition of Transition.java, there is a possible way to bypass touch filtering restrictions due to a tapjacki
In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This
In FuseDaemon.cpp, there is a possible out of bounds write due to memory corruption. This could lead to local escalation
In multiple functions of Permissions.java, there is a possible way to override the state of the user's location permissi
In multiple functions of ConnectionServiceWrapper.java, there is a possible way to retain a permission forever in the ba
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknow
A vulnerability was detected in SourceCodester Online Farm Management System 1.0. Affected by this vulnerability is an u
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. This impacts an unknown function of t
Foxit PDF Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerab
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo
Foxit PDF Reader PRC File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown function
Oxford Instruments Imaris Viewer IMS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerab
Oxford Instruments Imaris Viewer IMS File Parsing Uninitialized Pointer Remote Code Execution Vulnerability. This vulner
NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local att
Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulne
Realtek RTL8811AU rtwlanu.sys N6CSet_DOT11_CIPHER_DEFAULT_KEY Heap-based Buffer Overflow Local Privilege Escalation Vuln
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulne
Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation V
Anritsu ShockLine CHX File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerabi
Anritsu ShockLine CHX File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows re
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to
ATEN eco DC Missing Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to esca
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown fu
There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address w
There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitr
There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid source address whe
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started