The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje
Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_
An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) vi
An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensi
An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a
An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial
Time-of-check time-of-use race condition for some Intel(R) Battery Life Diagnostic Tool software before version 2.4.1 ma
Use after free in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23.80 may al
Insufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authent
NULL pointer dereference in some Intel(R) PROSet/Wireless WiFi and Killerâ„¢ WiFi software for Windows before version 23
Improper access control in some Intel(R) Graphics Driver software installers may allow an authenticated user to potentia
Improper input validation in the firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow an authent
Improper access control in some Intel(R) Graphics software may allow an authenticated user to potentially enable escalat
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user
NULL pointer dereference for some Intel(R) MLC software before version v3.11b may allow an authenticated user to potenti
Out-of-bounds write for some Intel(R) QuickAssist Technology software before version 2.2.0 may allow an authenticated us
Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentiall
Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged use
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl
Improper input validation in XmlCli feature for UEFI firmware for some Intel(R) processors may allow privileged user to
Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a p
Improper input validation in some Intel(R) System Security Report and System Resources Defense firmware may allow a priv
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user
Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a p
Improper input validation in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enabl
Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enabl
Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R
Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) S
An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devic
parse-duraton is software that allows users to convert a human readable duration to milliseconds. Versions prior to 2.1.
Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a
CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Poli
Koa is expressive middleware for Node.js using ES2017 async functions. Prior to versions 0.21.2, 1.7.1, 2.15.4, and 3.0.
go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1
mailcow: dockerized is an open source groupware/email suite based on docker. Prior to version 2025-01a, a vulnerability
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a command injection vulnerability in the SetVirtualServerSettings
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, th
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework impleme
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can le
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execut
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 1
In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through impro
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0
A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0
A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started