In the Linux kernel, the following vulnerability has been resolved: mm: fix a UAF when vma->mm is freed after vma->vm_r
A missing authorization vulnerability in Lexmark Cloud Services badge management allows attacker to reassign badges with
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to
An unauthenticated remote attacker can get access without password protection to the affected device. This enables the u
The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in
Multiple FunnelKit plugins are vulnerable to Sensitive Information Exposure via the wf_get_cookie shortcode. This makes
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the
The Sante PACS Server Web Portal sends credential information without encryption.
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a deni
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applicati
An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate pri
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/form
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/f
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFi
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons
Thermo Fisher Scientific ePort through 3.0.0 has Incorrect Access Control.
Shaarli is a minimalist bookmark manager and link sharing service. Prior to 0.15.0, the input string in the cloud tag pa
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerab
An Insecure Direct Object Reference (IDOR) vulnerability was identified in the `POST /v1/templates` endpoint of the Luna
IBM Storage Virtualize 8.4, 8.5, 8.6, and 8.7 could allow an authenticated user to escalate their privileges in an SSH s
IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially cr
An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user accou
CWE-59: Improper Link Resolution Before File Access ('Link Following') vulnerability exists that could cause arbitrary
CWE-20: Improper Input Validation vulnerability exists that could cause a Denial Of Service when specific crafted FTP co
In engineer mode service, there is a possible command injection due to improper input validation. This could lead to loc
A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows
A vulnerability was determined in Tenda AC20 16.03.08.12. This issue affects the function sub_48E628 of the file /goform
A vulnerability was found in Tenda AC20 16.03.08.12. This vulnerability affects the function save_virtualser_data of the
A vulnerability has been found in Tenda AC20 16.03.08.12. This affects the function set_qosMib_list of the file /goform/
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffe
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in the compo
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bound read in smb2_write ksmbd_s
The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via th
The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Delay put pmc->idev in mld_del_delrec(
In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the rece
In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP71
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix skb size by
In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix device refcount leak in atrtr_c
In the Linux kernel, the following vulnerability has been resolved: tracing: Add down_write(trace_event_sem) when addin
In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe(
In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix potential use-after-free in airoha
In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced regulator disable
In the Linux kernel, the following vulnerability has been resolved: net: libwx: properly reset Rx ring descriptor When
In the Linux kernel, the following vulnerability has been resolved: comedi: pcl812: Fix bit shift out of bounds When c
In the Linux kernel, the following vulnerability has been resolved: comedi: aio_iiro_16: Fix bit shift out of bounds W
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject %p% format string in bprintf-like helpe
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started