A vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this
A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by t
A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is
A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects s
A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the functio
A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file o
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when
Meshtastic is an open source mesh networking solution. In versions from 2.5.0 to before 2.6.11, the flashing procedure o
A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polk
The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if maliciou
ACL configured in ip_allow.config or remap.config does not use IP addresses that are provided by PROXY protocol. Users
A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, which could execute
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the D
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP e
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
Use after free in Metrics in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially exploit heap
Integer overflow in V8 in Google Chrome prior to 137.0.7151.119 allowed a remote attacker to potentially perform out of
An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP Se
A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic
Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to
A missing length check in `ogs_pfcp_subnet_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 an
A missing length check in `ogs_pfcp_dev_add` function from PFCP library, used by both smf and upf in open5gs 2.7.2 and e
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE)
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 could allow a privileged user to escalate their privilege
SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information vi
Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php.
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ
In the Linux kernel, the following vulnerability has been resolved: crypto: arm64/poly1305 - fix a read out-of-bound A
In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: Fix a UAF bug on the error path of p
In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Initialize Xen timer only once Add a
In the Linux kernel, the following vulnerability has been resolved: drm/fb-helper: Fix out-of-bounds access Clip memor
In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix linkwatch use-after-free on disconnect
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix KASAN use-after-free Read in compute_effec
In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Allow waiting for commands to complete on
In the Linux kernel, the following vulnerability has been resolved: coresight: Clear the connection field properly cor
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: do not allow SET_ID to refer
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: do not allow CHAIN_ID to refe
In the Linux kernel, the following vulnerability has been resolved: md-raid10: fix KASAN warning There's a KASAN warni
In the Linux kernel, the following vulnerability has been resolved: selinux: Add boundary check in put_entry() Just li
In the Linux kernel, the following vulnerability has been resolved: spi: tegra20-slink: fix UAF in tegra_slink_remove()
In the Linux kernel, the following vulnerability has been resolved: spi: Fix simplification of devm_spi_register_contro
In the Linux kernel, the following vulnerability has been resolved: tools/power turbostat: Fix file pointer leak Curre
In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix potential buffer overflow in ni_set
In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Align upwards buffer size The har
In the Linux kernel, the following vulnerability has been resolved: ath9k: fix use-after-free in ath9k_hif_usb_rx_cb S
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - don't sleep when in softirq
In the Linux kernel, the following vulnerability has been resolved: wifi: wil6210: debugfs: fix info leak in wil_write_
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started