In the Linux kernel, the following vulnerability has been resolved: ice: add NULL check in eswitch lag check The funct
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix irq-disabled in local_bh_enable() The r
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a c
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix the smbd_response slab to allow usercopy
In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix kernel crash when hard resetti
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix oops due to non-existence of prealloc ba
In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This
In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Clear all LMTT pages on alloc Our LMEM
In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency ca
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: discard erroneous disassoc frames on
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial
In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with
The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions u
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac
Claude Code is an agentic coding tool. Prior to version 1.0.4, it's possible to bypass the Claude Code confirmation prom
HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized rea
Server-Side Request Forgery (SSRF) vulnerability in Drupal AI SEO Link Advisor allows Server Side Request Forgery.This i
Missing Authorization vulnerability in Drupal Config Pages allows Forceful Browsing. This issue affects Config Pages: f
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerabili
A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability.
A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabi
Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnera
A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of
A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /
A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown fun
A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown fu
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Tekno
A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi
A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform
A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /a
A vulnerability has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of th
A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cg
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unkno
A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed o
The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1
The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient
A vulnerability was identified in SourceCodester Online Bank Management System up to 1.0. This issue affects some unknow
A vulnerability was determined in SourceCodester Online Bank Management System up to 1.0. This vulnerability affects unk
A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\
A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.0. This vulnerability affects unknown code
A vulnerability was identified in PHPGurukul Online Shopping Portal Project 2.0. This affects an unknown part of the fil
A vulnerability was determined in PHPGurukul Online Shopping Portal Project 2.0. Affected by this issue is some unknown
A vulnerability was found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this vulnerability i
A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown func
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started