In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Implement a crw lock Unlike the cha
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Improve CCA CPRB length and overflow c
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Improve EP11 CPRB length and overflow
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Improve EP11 CPRB domain handling with
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate GEM_CREATE domain combinations
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix UVD decode image min size calculati
In the Linux kernel, the following vulnerability has been resolved: xfs: propagate errors from xfs_rtginode_load xfs_r
In the Linux kernel, the following vulnerability has been resolved: xfs: fix off-by-one in rtrefcount btree root level
In the Linux kernel, the following vulnerability has been resolved: xfs: bounds-check buffer log item's dirty bitmap x
In the Linux kernel, the following vulnerability has been resolved: xfs: avoid UAF on sc->tempip in xrep_tempfile_creat
In the Linux kernel, the following vulnerability has been resolved: xfs: fix exchange-range reflink flag clearing issue
In the Linux kernel, the following vulnerability has been resolved: ceph: fix hanging __ceph_get_caps() with stale mds_
In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2562: Validate values for volume writes t
In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: k3: set hdma clock as critical HDMA
In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - fix rctx->cryptlen calculation in t
In the Linux kernel, the following vulnerability has been resolved: af_unix: Unlink scc_entry in unix_del_edge(). Kyle
In the Linux kernel, the following vulnerability has been resolved: ovpn: fix NULL dereference when killing missing key
In the Linux kernel, the following vulnerability has been resolved: perf: Reject exited events as group leaders perf_e
In the Linux kernel, the following vulnerability has been resolved: ovpn: defer key slot crypto freeing to workqueue K
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix refcount race between list:se
In the Linux kernel, the following vulnerability has been resolved: ipvs: revalidate ihl to prevent out-of-bounds acces
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: avoid deadlock when canceling IRQ affini
In the Linux kernel, the following vulnerability has been resolved: veth: fix queue index used to wake the peer txq in
In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix NULL pointer dereference in non-MSI-
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_u32: skip hash tables in u32_bind_cl
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: reject dev-bound programs bound
IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and
LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStruc
Rently Smart Home versions 20.1.0 and prior are vulnerable to an Insufficiently Protected Credentials vulnerability. Thi
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in TÜBİTAK BİLGEM Sof
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.
A stack-based buffer overflow vulnerability exists in the Dia diagram editor when processing Network Bus objects from Di
Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attack
The Classified Listing - Mobile Number Verification plugin for WordPress is vulnerable to Authentication Bypass in all v
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear
OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms
TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods i
mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSa
StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Conne
A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote
The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by pa
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authen
EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attack
Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can
CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability.
Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, res
An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by comm
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started