Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr
By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th
A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n
The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native G
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit
Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started