SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app expli
A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Swi
A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML
A cross-site scripting (XSS) vulnerability in Emlog Pro v2.5.4 allows attackers to execute arbitrary web scripts or HTML
This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c
In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no
The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back i
The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in
The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in th
The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back i
The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in t
The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it ba
The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it bac
The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before ou
Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which comp
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows i
In the Linux kernel, the following vulnerability has been resolved: i40e: Fix call trace in setup_tx_descriptors After
In the Linux kernel, the following vulnerability has been resolved: tty: goldfish: Fix free_irq() on remove Pass the c
In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory corruption in VF driver Disable VF
In the Linux kernel, the following vulnerability has been resolved: block: Fix handling of offline queues in blk_mq_all
In the Linux kernel, the following vulnerability has been resolved: bus: fsl-mc-bus: fix KASAN use-after-free in fsl_mc
In the Linux kernel, the following vulnerability has been resolved: zonefs: fix zonefs_iomap_begin() for reads If a re
In the Linux kernel, the following vulnerability has been resolved: scsi: ibmvfc: Allocate/free queue resource only dur
In the Linux kernel, the following vulnerability has been resolved: mm/slub: add missing TID updates on slab deactivati
In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom b
In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free Read in tipc_named_reinit
In the Linux kernel, the following vulnerability has been resolved: igb: fix a use-after-free issue in igb_clean_tx_rin
In the Linux kernel, the following vulnerability has been resolved: block: disable the elevator int del_gendisk The el
In the Linux kernel, the following vulnerability has been resolved: virtio_net: fix xdp_rxq_info bug after suspend/resu
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix list double add in uvcg_video
In the Linux kernel, the following vulnerability has been resolved: iio: trigger: sysfs: fix use-after-free on remove
In the Linux kernel, the following vulnerability has been resolved: dm raid: fix accesses beyond end of raid member arr
In the Linux kernel, the following vulnerability has been resolved: net: tun: unlink NAPI from device on destruction S
In the Linux kernel, the following vulnerability has been resolved: linux/dim: Fix divide by 0 in RDMA DIM Fix a divid
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race on unaccepted mptcp sockets When t
In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free after 802.3ad slav
In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_creat
In the Linux kernel, the following vulnerability has been resolved: srcu: Tighten cleanup_srcu_struct() GP checks Curr
In the Linux kernel, the following vulnerability has been resolved: cgroup: Use separate src/dst nodes when preloading
In the Linux kernel, the following vulnerability has been resolved: drm/panfrost: Fix shrinker list corruption by madvi
In the Linux kernel, the following vulnerability has been resolved: ima: Fix a potential integer overflow in ima_apprai
In the Linux kernel, the following vulnerability has been resolved: drm/i915/selftests: fix subtraction overflow bug O
In the Linux kernel, the following vulnerability has been resolved: sfc: fix use after free when disabling sriov Use a
In the Linux kernel, the following vulnerability has been resolved: powerpc/xive/spapr: correct bitmap allocation size
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: avoid skb access on nf_stolen
In the Linux kernel, the following vulnerability has been resolved: power: supply: core: Fix boundary conditions in int
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started