Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can expl
A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by
A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the fu
In the Linux kernel, the following vulnerability has been resolved: dlm: fix dlm_recover_members refcount on error If
In the Linux kernel, the following vulnerability has been resolved: nfs/localio: must clear res.replen in nfs_local_rea
In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Terminate the erratum_1386_microcode a
In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Several fixes to bpf_msg_pop_data Se
In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix incorrect IFH SRC_PORT field
In the Linux kernel, the following vulnerability has been resolved: ionic: Fix netdev notifier unregister on failure I
In the Linux kernel, the following vulnerability has been resolved: io_uring: check if iowq is killed before queuing t
A vulnerability, which was classified as critical, has been found in 1000 Projects Human Resource Management System 1.0.
GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesys
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unk
The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a se
A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b
In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unlo
In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Fix and protect memory allocation of
In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an
In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix soft lockups in fib6_select_path under hi
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix potential double remove of hotplug sl
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Use dynamic allocation for CU occupancy
In the Linux kernel, the following vulnerability has been resolved: bpf: fix recursive lock when verdict program return
In the Linux kernel, the following vulnerability has been resolved: brd: defer automatic disk creation until module ini
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node blkaddr in tru
In the Linux kernel, the following vulnerability has been resolved: sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset tran
In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_
In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - add error check in the ahash_hmac_ini
In the Linux kernel, the following vulnerability has been resolved: powerpc/mm/fault: Fix kfence page fault reporting
In the Linux kernel, the following vulnerability has been resolved: powerpc/fadump: Move fadump_cma_init to setup_arch(
Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may ca
Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerabilit
Some Huawei wearables have a permission management vulnerability.
Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful explo
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern
Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only sy
A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive
An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command inje
HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_c
An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0
Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.
An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all
A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulne
changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se
LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started