The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via
The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in al
Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injectio
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthoriz
The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable to
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
The Flex Mag - Responsive WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data th
The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the '
A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue a
A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vu
A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This
A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0.
A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this
A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by th
A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affect
The Homey theme for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.3. This is du
A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3.
ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allo
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a
An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized
Buffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web U
Incorrect access control in the KSRTC AWATAR app of Karnataka State Road Transport Corporation v1.3.0 allows to view sen
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by th
An issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990,
An issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990,
In the Linux kernel, the following vulnerability has been resolved: block: don't revert iter for -EIOCBQUEUED blkdev_r
In the Linux kernel, the following vulnerability has been resolved: landlock: Handle weird files A corrupted filesyste
In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Stop active perfmon if it is being destroy
In the Linux kernel, the following vulnerability has been resolved: KVM: Explicitly verify target vCPU is online in kvm
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix crash during unbind if gpio un
IBM Concert Software 1.0.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force
A deserialization of untrusted data vulnerability exists in NI G Web Development Software that may result in arbitrary c
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't flush non-uploaded STAs If S
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Add locks for usb_drive
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of fie
In the Linux kernel, the following vulnerability has been resolved: bpf: Cancel the running bpf_timer through kworker f
In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - do not transfer req when tegra init
In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: remove unused check_buddy_priv Comm
In the Linux kernel, the following vulnerability has been resolved: bpf: bpf_local_storage: Always use bpf_mem_alloc in
In the Linux kernel, the following vulnerability has been resolved: rtc: pcf85063: fix potential OOB write in PCF85063
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject struct_ops registration that uses modul
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_tcm: Don't free command immediately
In the Linux kernel, the following vulnerability has been resolved: staging: media: max96712: fix kernel oops when remo
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix handling of received connection abort F
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started