Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre
Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to
Logto omits validation of the SAML <Conditions> element, enabling attackers to strip time and audience restrictions and
Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing au
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, a
Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField()
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver
Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions.
Contributor Local File Inclusion in Vino <= 1.9 versions.
Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions.
Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
Contributor SQL Injection in MapSVG <= 8.14.0 versions.
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via develop
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configur
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-loca
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started