Multiple switches are affected by an out-of-bounds write vulnerability. This vulnerability is caused by insufficient inp
The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stored
The Competition Form WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by thi
A vulnerability classified as critical was found in SourceCodester Best Employee Management System 1.0. Affected by this
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affec
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a sess
AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers
Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C
An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handli
In shouldSkipForInitialSUW of AdvancedPowerUsageDetail.java, there is a possible way to bypass factory reset protections
In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an
In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead
In onCreate of ChooserActivity.java, there is a possible way to bypass factory reset protections due to a missing permis
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privil
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation
In TBD of TBD, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation
In _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. Thi
In DevmemXIntMapPages of devicemem_server.c, there is a possible arbitrary code execution due to an integer overflow. Th
In RGXMMUCacheInvalidate of rgxmem.c, there is a possible arbitrary code execution due to a race condition. This could l
Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware.
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all nam
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permissi
In TdlsexRxFrameHandle of the MTK WLAN driver, there is a possible out of bounds write due to a missing bounds check. Th
In JetBrains ReSharper before 2024.3.4, 2024.2.8, and 2024.1.7, Rider before 2024.3.4, 2024.2.8, and 2024.1.7, dotTrace
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The file upload fea
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. The external storag
Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior versi
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memor
The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al
The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees'
NVIDIA GPU display driver for Windows and Linux contains a vulnerability where data is written past the end or before th
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause memory cor
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could le
Using ParsePKCS1PrivateKey to parse a RSA key that is missing the CRT values would panic when verifying that the key is
Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server
When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged pr
CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a G
Insecure Permissions vulnerability in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a cra
An issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validat
Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized
In AXESS ACS (Auto Configuration Server) through 5.2.0, unsanitized user input in the TR069 API allows remote unauthenti
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3
A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Vent
A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A ma
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, ma
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started