In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Bad drive in topology results kernel
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix kernel-infoleak in nilfs_ioctl_wrap_cop
In the Linux kernel, the following vulnerability has been resolved: codel: remove sch->q.qlen check before qdisc_tree_r
In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class h
Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D
Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS
The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versi
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver al
Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forge
Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check
The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via
The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check o
A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. This vulnerabilit
A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. Affected by this
A vulnerability was found in itsourcecode Restaurant Management System 1.0. It has been classified as critical. This aff
A vulnerability has been found in PHPGurukul Employee Record Management System 1.3 and classified as critical. Affected
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of t
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com
A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno
A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. Affected by this vulnerability is
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. Affected is an unknown function
A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as critical. This v
An insecure file system permissions vulnerability in MSP360 Backup 4.3.1.115 allows a low privileged user to execute com
Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow
Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an
Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unautho
Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telne
Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda R
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. A
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption wi
MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. T
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to ve
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sendin
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for send
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next ho
In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commi
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix null-ptr-deref when xps sysfs alloc fai
In the Linux kernel, the following vulnerability has been resolved: net: sched: Fix use after free in red_enqueue() We
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: netlink notifier might race t
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flow rule object from
In the Linux kernel, the following vulnerability has been resolved: ipvs: fix WARNING in ip_vs_app_net_cleanup() Durin
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free caused by l2ca
In the Linux kernel, the following vulnerability has been resolved: net: mdio: fix undefined behavior in bit shift for
In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix possible leaked pernet namespace in sm
In the Linux kernel, the following vulnerability has been resolved: i2c: piix4: Fix adapter not be removed in piix4_rem
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started