In multiple locations, there is a possible out of bounds write due to a use after free. This could lead to remote code e
In dng_lossless_decoder::HuffDecode of dng_lossless_jpeg.cpp, there is a possible way to cause a crash due to uninitiali
In multiple locations, there is a possible way to overlay the installation confirmation dialog due to a tapjacking/overl
In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error i
In main of main.cpp, there is a possible way to bypass SELinux due to a logic error in the code. This could lead to loca
In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This coul
A vulnerability was determined in Campcodes Online Water Billing System 1.0. This affects an unknown function of the fil
Directory traversal vulnerability in AbanteCart version 1.4.2 allows unauthenticated attackers to gain access to sensiti
Use after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap c
NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious dat
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by a
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious da
NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick vers
Microsoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability. This vulnerability allows remote at
A non-primary administrator user with admin rights to the web interface but without shell access permissions can display
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a remote attacker to conduct phishing attacks, using an open
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could allow a local user to execute arbitrary code on the system due t
jsPDF is a library to generate PDFs in JavaScript. Prior to 3.0.2, user control of the first argument of the addImage me
The Event List plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0.4. T
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sani
A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1
A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.
A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.
Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "devi
Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the data
An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel
Delta Electronics COMMGR has Code Injection vulnerability.
Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.
A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected by this issue is some u
A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this vulnerability is an unkn
A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. This impacts an unknown
A vulnerability was found in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing of
The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and
A vulnerability has been found in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code
A flaw has been found in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /managem
A vulnerability was detected in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown fun
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this vulnerabili
The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up
A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue af
A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /gofor
A weakness has been identified in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown par
A security flaw has been discovered in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue
A vulnerability was determined in Campcodes Online Water Billing System 1.0. Affected is an unknown function of the file
A vulnerability has been found in itsourcecode Apartment Management System 1.0. This affects an unknown function of the
A flaw has been found in itsourcecode Apartment Management System 1.0. The impacted element is an unknown function of th
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off conditio
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started