In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m
The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor
An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a
An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause
Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new s
A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7
An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying f
Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive co
An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset v
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and
The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allo
An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data
A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th
FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit
A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors
A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp
Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera
A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communicati
Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between contr
A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3
OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci
OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi
Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature t
Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to exe
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN53
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started