The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ
Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cl
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthen
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) d
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The end
Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code in
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code ins
Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the rende
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality o
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corru
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execu
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne
Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK befo
The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process an
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue af
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5,
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allo
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that all
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by sup
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows rem
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility tha
Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43
Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unau
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started