A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the fi
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the comp
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the fil
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web ser
A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component Securi
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements
Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rende
SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package nam
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/get
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which pro
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized wit
keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication,
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers t
Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an at
Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads
A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage
A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLeng
A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_req
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and i
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode.
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verificati
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication,
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the
pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak
su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t an
RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-exi
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attacker
BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that al
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first throu
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, gr
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does
The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vC
mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.
Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylo
free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL state
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session ope
When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 22,671 CVE records rated HIGH in our database. Of these, 48 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started