In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_c
In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ordering of qlen adjustment Change
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenti
There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does no
There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on speci
There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker c
An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a con
An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mis
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affec
A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected b
A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affec
The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.
Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated u
A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is
A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln
A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been declared as critical. This v
A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical.
A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this issue is the
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this vulnera
A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affec
A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0.
Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of
A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit
A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. This affects
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System
A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affec
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by th
A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by
Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the
A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been classified as critical. Affe
A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Th
A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conv
A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prio
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged
The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via t
The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPr
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privilege
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_sc
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSc
In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_na
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in h
In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i
In the Linux kernel, the following vulnerability has been resolved: svcrdma: Address an integer overflow Dan Carpenter
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started