JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific condi
An authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited repository acc
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written ou
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentia
Incorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog administra
Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authe
Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a r
An event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileged use
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a valida
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the pl
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory alloca
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access control
Next.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted reque
Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 thr
Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the termin
Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated term
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-adm
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser
facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unau
facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows u
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows
Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica
The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote att
Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows una
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <= 4.5.11 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer & Embedder <= 1.4.2 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Subscriber Insecure Direct Object References (IDOR) in Paid Member Subscriptions <= 3.0.7 versions.
Administrator SQL Injection in Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce <= 2.10.22 versio
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started