Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Windows Domain Name Service Remote Code Execution Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Windows IP Routing Management Snapin Remote Code Execution Vulnerability
Input Method Editor (IME) Remote Code Execution Vulnerability
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
Windows Remote Desktop Services Denial of Service Vulnerability
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
Windows Task Scheduler Elevation of Privilege Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft/Muzic Remote Code Execution Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha
GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtde
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in e
GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in q
GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.
GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover
GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discove
GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identif
OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit th
Microsoft Office Elevation of Privilege Vulnerability
Microsoft System Center Elevation of Privilege Vulnerability
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated a
A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects
Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit he
Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corr
XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows
GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all
GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allo
Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut
GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin
GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started