Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Bookly <= 27.7 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Broken Authentication in Ziina <= 1.2.21 versions.
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions.
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Enquiry for WooCommerce <= 2.2.34.43 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.34.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Unauthenticated Cross Site Scripting (XSS) in Grand Photography <= 5.7.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Google Maps Pro <= 10.1.02 versions.
Unauthenticated Cross Site Scripting (XSS) in Breakdance <= 2.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions.
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailP
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Contributor SQL Injection in eRoom <= 1.7.1 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network b
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - T
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths c
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-up
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin
RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG
A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform
The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'
The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version
The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the
A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started