A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit
A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System
A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as c
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function ro
A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected
A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a
Microsoft Dynamics 365 Sales Spoofing Vulnerability
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privil
An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password
Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera
A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil
There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled
A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo
Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored da
Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to use
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"
Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corrupti
An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using d
Crafted Binder Request Causes Heap UAF in MediaServer
Information disclosure possible while audio playback.
Information disclosure due to uninitialized variable.
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory.
Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to vi
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convi
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactur
An image with a version lower than the fuse version may potentially be booted lead to improper authentication.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started