In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flo
In the Linux kernel, the following vulnerability has been resolved: afs: Fix the maximum cell name length The kafs fil
In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: cookie_hmac_alg: avoid using current-
In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: auth_enable: avoid using current->nsp
In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: udp_port: avoid using current->nsprox
In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix waker_bfqq UAF after bfq_split_bfqq
A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNet
A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functiona
A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulne
IBM Safer Payments 6.4.0.00 through 6.4.2.07, 6.5.0.00 through 6.5.0.05, and 6.6.0.00 through 6.6.0.03 could allow a rem
IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacke
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote
A buffer overflow vulnerability has been identified in the Internet Printing Protocol (IPP) in various Lexmark devices.
In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lea
In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app du
In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This
In ip6_append_data of ip6_output.c, there is a possible way to achieve code execution due to a heap buffer overflow. Thi
In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This c
zot is a production-ready vendor-neutral OCI image registry. The group data stored for users in the boltdb database (met
In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could le
In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profil
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictio
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as criti
A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as cr
Belledonne Communications Linphone-Desktop is vulnerable to a NULL Dereference vulnerability, which could allow a remo
Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by t
A vulnerability classified as critical was found in code-projects Admission Management System 1.0. Affected by this vuln
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbi
Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi
A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala be
Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attacke
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started