Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ContentLocalized T
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chetan Khandla Woo
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fireantology Histo
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anil Jailta FWD Sl
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in davidpuc Simple sh
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in stephanemartinw Ma
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the
A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missi
Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `UE Context Release Request` packet handler. A packet
Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet
The NextEPC MME <= 1.0.1 (fixed in commit a8492c9c5bc0a66c6999cb5a263545b32a4109df) contains a stack-based buffer overfl
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu
The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu
Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may di
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 a
With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This i
In DGifSlurp of dgif_lib.c, there is a possible out of bounds write due to an integer overflow. This could lead to remot
In growData of Parcel.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to
In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to bypass parcel mismatch mit
In onCreate of NotificationAccessConfirmationActivity.java , there is a possible way to hide an app with notification ac
In writeInplace of Parcel.cpp, there is a possible out of bounds write. This could lead to local escalation of privilege
In applyTaskFragmentOperation of WindowOrganizerController.java, there is a possible way to launch arbitrary activities
In multiple locations, there is a possible failure to persist permissions settings due to resource exhaustion. This coul
In multiple functions of ConnectivityService.java, there is a possible way for a Wi-Fi AP to determine what site a devic
In multiple functions of CompanionDeviceManagerService.java, there is a possible way to grant permissions without user c
In multiple functions of AccountManagerService.java, there is a possible way to bypass permissions and launch protected
In gatts_process_read_req of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This cou
In gatts_process_find_info of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This co
In multiple locations, there is a possible way to obtain access to a folder due to a tapjacking/overlay attack. This cou
In build_read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to a missing bounds check. This could
In multiple locations, there is a possible way to obtain any system permission due to a logic error in the code. This co
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in
A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Serv
A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service
A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co
The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to co
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started