A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown function
A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library A
XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when ev
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalatio
GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitra
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in
Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only
Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image
Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint
SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints,
SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.s
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xm
Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-em
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the f
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_l
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System exec
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or wr
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component
The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a
The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a S
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa
In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i
In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a
In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects B
In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local e
In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local es
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv
In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (pro
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens
In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allocates buffer from unchecked 24-bit length. This is
In Bouncy Castle for Java before 1.85, OER parser recurses without depth limit on self-referential IEEE 1609.2 schema. T
In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue
In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue al
In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also a
In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started