Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privil
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/w
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthentica
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through
In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null poi
Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was alread
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an
Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration.
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req
whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote atta
An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distr
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN reposito
Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custo
Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configu
Midday allows any member of a team to delete it. The delete procedure in apps/api/src/trpc/routers/team.ts authorises th
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLogin
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a spe
bestzip builds the argument list for the system zip utility without separating options from operands. The destination ar
FiftyOne renders a dataset field's description as markup. The sidebar field-information component at app/packages/core/s
In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path
In the Linux kernel, the following vulnerability has been resolved: s390/qeth: validate user buffer length in SNMP and
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol acc
In the Linux kernel, the following vulnerability has been resolved: drm/shmem_helper: Check VMA boundaries for PMD mapp
In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer
In the Linux kernel, the following vulnerability has been resolved: fbdev: clear fb_info->mode before deleting a videom
In the Linux kernel, the following vulnerability has been resolved: fbdev: core: Fix pointer desynchronization in fb_io
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring pack
In the Linux kernel, the following vulnerability has been resolved: Input: cs40l50-vibra - validate custom data from us
In the Linux kernel, the following vulnerability has been resolved: Input: focaltech - fix array out-of-bounds in focal
In the Linux kernel, the following vulnerability has been resolved: Input: byd - synchronize timer deletion before free
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero report size on F54 wor
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size t
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - block s_input when F54 queu
In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix error path in devm_qce_register_a
In the Linux kernel, the following vulnerability has been resolved: openrisc: signal: do not restore privileged SR bits
In the Linux kernel, the following vulnerability has been resolved: Input: sur40 - fix input device registration orderi
In the Linux kernel, the following vulnerability has been resolved: mmc: atmel-mci: Fix use-after-free in atmci_remove
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Free all memory if cp_init() fails
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The init
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure index for read/write regions
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Fix out of bounds check on CCW array
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Move cp cleanup out of not operation
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Selectively expand io_mutex The io_
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started