The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, mac
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted gi
A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links
An authenticated user without user administrative permissions could change the administrator Account Name.
An unauthenticated user could discover account credentials via a brute-force attack without rate limiting
IBM 4769 Developers Toolkit 7.0.0 through 7.5.52 could allow a remote attacker to cause a denial of service in the Hardw
SEL-5037 Grid Configurator contains an overly permissive Cross Origin Resource Sharing (CORS) configuration for a data g
ARTEC EMA Mail 6.92 allows CSRF.
A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a
EspoCRM is a free, open-source customer relationship management platform. Prior to version 9.0.8, HTML Injection in Know
An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluet
The KFOX from KingFor has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privilege to up
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Th
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by
A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0
A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affect
A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn
A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the fil
A vulnerability was found in MTSoftware C-Lodop 6.6.1.1 on Windows. It has been rated as critical. This issue affects so
A vulnerability was found in Hainan ToDesk 4.7.6.3. It has been declared as critical. This vulnerability affects unknown
A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19
A vulnerability, which was classified as critical, has been found in Discord 1.0.9188 on Windows. Affected by this issue
In BlueWave Checkmate through 2.0.2 before b387eba, a profile edit request can include a role parameter.
A vulnerability, which was classified as critical, has been found in PHPGurukul e-Diary Management System 1.0. This issu
A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects
A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn
A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. Affe
A vulnerability was found in SourceCodester Online College Library System 1.0. It has been classified as critical. Affec
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btsdio: fix use after free bug in btsdio
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_i
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Privilege Escalation due to insuff
The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L
A vulnerability was found in TOTOLINK T10, A3100R, A950RG, A800R, N600R, A3000RU and A810R 4.1.8cu.5241_B20210927. It ha
IBM Storage Scale 5.2.2.0 and 5.2.2.1, under certain configurations, could allow an authenticated user to execute privil
Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set,
A vulnerability, which was classified as critical, was found in JAdmin-JAVA JAdmin 1.0. Affected is the function toLogin
A vulnerability, which was classified as critical, has been found in Campcodes Online Food Ordering System 1.0. This iss
A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affect
A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn
A vulnerability was found in Campcodes Online Food Ordering System 1.0. It has been rated as critical. Affected by this
In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by m
code-server runs VS Code on any machine anywhere through browser access. Prior to version 4.99.4, a maliciously crafted
A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this
A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. Affected is an
A vulnerability was found in itsourcecode Gym Management System 1.0 and classified as critical. This issue affects some
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started