There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to
Improper session invalidation in the component /edms/change-password.php of PHPGurukul e-Diary Management System v1 allo
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v
Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v
Improper session invalidation in the component /doctor/change-password.php of PHPGurukul Doctor Appointment Management S
Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management Syst
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challe
IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacke
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query
A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a progr
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. Affected by this
Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse. This issue affects PhishPro:
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Fix OOB read on empty string
In the Linux kernel, the following vulnerability has been resolved: HID: core: ensure the allocated report buffer can c
In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw
In the Linux kernel, the following vulnerability has been resolved: mptcp: make fallback action and fallback decision a
In the Linux kernel, the following vulnerability has been resolved: soundwire: Revert "soundwire: qcom: Add set_channel
In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8
In the Linux kernel, the following vulnerability has been resolved: iio: backend: fix out-of-bound write The buffer is
In the Linux kernel, the following vulnerability has been resolved: comedi: das16m1: Fix bit shift out of bounds When
In the Linux kernel, the following vulnerability has been resolved: comedi: das6402: Fix bit shift out of bounds When
In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggre
In the Linux kernel, the following vulnerability has been resolved: smc: Fix various oops due to inet_sock type confusi
In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix VLAN 0 refcount imbalance of togglin
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been declared as critical. This vulnerabilit
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue i
A weakness has been identified in Vaelsys VaelsysV4 4.1.0. This vulnerability affects unknown code of the file /grid/vgr
A vulnerability was identified in Vaelsys VaelsysV4 up to 5.1.0/5.4.0. Affected by this issue is the function execute_Da
Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been classified as critical. This affects an
A vulnerability was found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this issue i
A vulnerability has been found in code-projects Exam Form Submission 1.0 and classified as critical. Affected by this vu
A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1.0. Affected is an u
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. This issue
A vulnerability classified as critical was found in code-projects Online Ordering System 1.0. This vulnerability affects
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulne
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unkno
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unkno
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started