Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissio
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-sec
Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Databa
Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html end
A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocati
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a doub
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
CWE-204: Observable Response Discrepancy
CWE-639 Authorization Bypass Through User-Controlled Key
CWE-639 Authorization Bypass Through User-Controlled Key
OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions pr
A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attack
Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
Memory corruption while processing simultaneous requests via escape path.
Memory corruption while processing IOCTL command with larger buffer in Bluetooth Host.
Transient DOS while creating NDP instance.
Memory corruption while processing specific files in Powerline Communication Firmware.
Memory corruption while processing DDI command calls.
Memory corruption while processing an IOCTL command with an arbitrary address.
Memory corruption while processing DDI call with invalid buffer.
Transient DOS while processing an ANQP message.
Transient DOS while processing a frame with malformed shared-key descriptor.
Memory corruption while handling client exceptions, allowing unauthorized channel access.
Transient DOS while processing CCCH data when NW sends data with invalid length.
Memory corruption while processing commands from A2dp sink command queue.
Memory corruption when using Virtual cdm (Camera Data Mover) to write registers.
Memory corruption when programming registers through virtual CDM.
Memory corruption when IOCTL interface is called to map and unmap buffers simultaneously.
Memory corruption while processing IOCTL command when multiple threads are called to map/unmap buffer concurrently.
Memory corruption while submitting blob data to kernel space though IOCTL.
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code
Vulnerability of improper processing of abnormal conditions in huge page separation. Impact: Successful exploitation of
Out-of-bounds write vulnerability in the skia module. Impact: Successful exploitation of this vulnerability may affect s
Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-a
Kenwood DMX958XR JKRadioService Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo
The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all vers
Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnera
EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started