In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This cou
In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protoc
A vulnerability, which was classified as critical, has been found in code-projects Online Medicine Guide 1.0. Affected b
A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerabil
A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerabili
A security vulnerability has been detected in code-projects Online Medicine Guide 1.0. This vulnerability affects unknow
A weakness has been identified in code-projects Online Medicine Guide 1.0. This affects an unknown part of the file /cus
A vulnerability has been found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1.0. A
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1
OpenNebula Community Edition (CE) before 7.0.0 and Enterprise Edition (EE) before 6.10.3 have a critical FireEdge race c
A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerab
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack bu
NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to esc
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index val
NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could
NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful
A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This iss
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerabili
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affect
A vulnerability was found in code-projects Wazifa System 1.0. It has been rated as critical. Affected by this issue is s
A vulnerability was found in code-projects Wazifa System 1.0. It has been declared as critical. Affected by this vulnera
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an un
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both t
Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "repor
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo
Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa
An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to
Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute
Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers
Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-
Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows
A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or
Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged he
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can
uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allow
MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren
MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren
MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren
MaterialX is an open standard for the exchange of rich material and look-development content across applications and ren
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started