An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ
NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause serv
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful e
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a rest
NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper lim
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash
NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful expl
Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown fun
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m
A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
Memory corruption while processing a packet with a size close to the maximum allowed value.
Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauth
Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr
A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY
The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b
Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc
Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa
Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request
Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu
Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con
In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand
In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P
In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab
Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc.
freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di
In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart r
In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started