In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when COWing tree bock and
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow w
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr
A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on
TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't es
tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API me
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in t
Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without ch
Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows u
Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global
Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.
Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.
Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryp
Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.
Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.
Memory corruption when IOCTL call is invoked from user-space to read board data.
Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers th
Memory corruption while processing IPA statistics, when there are no active clients registered.
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no add
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote
A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker co
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of
A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions
A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by th
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the C
An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the C
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests fo
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business l
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th
FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edi
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hi
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to i
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewTyp
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability,
In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with
In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to a
In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This coul
there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with
In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect boun
In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validat
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started