itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users t
An OpenSSH daemon listens on TCP port 22. There is a hard-coded entry in the "/etc/shadow" file in the firmware image fo
When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG conta
The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injection
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The cr
Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticat
Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.
Yandex Browser Lite for Android prior to version 21.1.0 allows remote attackers to cause a denial of service.
A vulnerability was found in projectworlds Online Time Table Generator 1.0. It has been rated as critical. Affected by t
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. Affected is an un
A vulnerability was found in projectworlds Online Time Table Generator 1.0 and classified as critical. This issue affect
A vulnerability has been found in projectworlds Online Time Table Generator 1.0 and classified as critical. This vulnera
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Th
In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API
In the Linux kernel, the following vulnerability has been resolved: parisc: Fix double SIGFPE crash Camm noticed that
In the Linux kernel, the following vulnerability has been resolved: fix a couple of races in MNT_TREE_BENEATH handling
In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in
This High severity PrivEsc (Privilege Escalation) vulnerability was introduced in versions: 9.12.0, 10.3.0, 10.4.0, and
In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Use is_kdump_kernel() to check for
In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix sc7280 lpass potential buffer overf
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent pro
In the Linux kernel, the following vulnerability has been resolved: riscv: module: Fix out-of-bounds relocation access
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix out-of-bounds access during mul
An authenticated user can modify application state data.
Password guessing limits could be bypassed when using LDAP authentication.
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be i
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN inter
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent rename with empty string Client can
In the Linux kernel, the following vulnerability has been resolved: smb: client: Avoid race in open_cached_dir with lea
In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-aft
In the Linux kernel, the following vulnerability has been resolved: xenbus: Use kref to track req lifetime Marek repor
In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by valid
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix duplicate pci_dev_put() in disable_sl
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid entry fetch in ath12k_dp_
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_
In the Linux kernel, the following vulnerability has been resolved: tracing: Verify event formats that have "%*p.." Th
In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for gu
In the Linux kernel, the following vulnerability has been resolved: ASoC: simple-card-utils: Fix pointer check in graph
In the Linux kernel, the following vulnerability has been resolved: btrfs: adjust subpage bit start based on sectorsize
In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG w
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential buffer overflow in parse_i
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_session_rpc_open
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix oob write in trace_seq_to_buffer() sy
In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: Fix unlocked deletion of default
In the Linux kernel, the following vulnerability has been resolved: xsk: Fix race condition in AF_XDP generic RX path
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: avoid NULL pointer dereference in
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk-star-emac: fix spinlock recursio
In the Linux kernel, the following vulnerability has been resolved: pds_core: remove write-after-free of client_id A u
In the Linux kernel, the following vulnerability has been resolved: net_sched: drr: Fix double list add in class with n
In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: Fix double list add in class with n
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started