There is an out of bounds write vulnerability due to improper bounds checking in displ2.dll when parsing a DSB file with
There is an out of bounds write vulnerability due to improper bounds checking resulting in an invalid address when parsi
There is a heap-based Buffer Overflow vulnerability due to improper bounds checking when parsing a DSB file with Digilen
There is an out of bounds write vulnerability due to improper bounds checking resulting in invalid data when parsing a D
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A use-after-free vulnerability in the write_interleav
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) An integer overflow vulnerability in the Vector::new
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Integer overflow and invalid input vulnerability in t
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) A null pointer dereference vulnerability in the input
An issue was discovered in rust-ffmpeg 0.3.0 (after comit 5ac0527) Null pointer dereference vulnerability in the name()
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover,
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering ab
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypa
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge ma
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacke
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which retur
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated atta
E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft OctoCloud allows Authentication Bypa
A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on cert
Unauthorized disclosure of sensitive data: Any user with `GET` or `LIST` permissions on `BundleDeployment` resources cou
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)
A weakness has been identified in alaneuler batteryKid up to 2.1 on macOS. The affected element is an unknown function o
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function
A vulnerability was identified in Tenda CH22 1.0.0.1. This issue affects the function formSetSambaConf of the file /gofo
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formexeCommand of the file
A vulnerability was found in Campcodes Farm Management System 1.0. This affects an unknown part of the file /reviewInput
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. In version
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In version 2025.8.0 in the ESP
A flaw has been found in Campcodes Computer Sales and Inventory System 1.0. The affected element is an unknown function
A vulnerability was detected in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the fil
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. This issue affects some unkn
A weakness has been identified in Tenda AC20 16.03.08.05. This vulnerability affects unknown code of the file /goform/fr
A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the
A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. Affected by this issue is some unk
A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerabil
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10,
A vulnerability was found in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the fil
A vulnerability was determined in TOTOLINK A702R 4.0.0-B20211108.1423. This issue affects the function sub_418030 of the
A vulnerability was found in TOTOLINK A702R 4.0.0-B20211108.1423. This vulnerability affects the function sub_4466F8 of
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20211108.1423. This affects the function sub_4162DC of the file
A flaw has been found in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this issue is the function sub_419BE0 of the f
A vulnerability was detected in TOTOLINK A702R 4.0.0-B20211108.1423. Affected by this vulnerability is the function sub_
Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft QR Menu allows Authentication Bypass
Cross-Site Request Forgery (CSRF) vulnerability in Akınsoft QR Menü allows Cross Site Request Forgery. This issue affec
Improper Validation of Certificate with Host Mismatch vulnerability in Akınsoft QR Menü allows HTTP Response Splitting.
A vulnerability was found in RemoteClinic up to 2.0. Impacted is an unknown function of the file /staff/edit-my-profile.
A vulnerability was detected in RemoteClinic up to 2.0. This affects an unknown part of the file /staff/edit.php. Perfor
A security vulnerability has been detected in SourceCodester Eye Clinic Management System 1.0. Affected by this issue is
A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown
In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additio
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started