rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by provi
WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).
A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an
A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affecte
A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnera
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, fr
A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by
A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buf
Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote aut
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unkn
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPEC
Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected produc
Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB
Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB A
Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products: ABB ASPECT - En
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or chan
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products:
Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected produc
Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX f
UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker
Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and f
The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress i
A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by
A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected i
In multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escala
An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service (DoS) via a crafted request.
An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to u
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0
binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no perm
The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to
The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead
In the Linux kernel, the following vulnerability has been resolved: netlink: terminate outstanding dump on socket close
In the Linux kernel, the following vulnerability has been resolved: sctp: fix possible UAF in sctp_v6_available() A lo
In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getat
In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to a
In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages
In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_op
In the Linux kernel, the following vulnerability has been resolved: bpf: sync_linked_regs() must preserve subreg_def R
IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authent
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The Saa
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Disp
Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause
The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started