Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attac
An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scrip
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backen
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label
The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerab
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerabil
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function.
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. T
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnera
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vu
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnera
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerabi
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerabil
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerabilit
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cg
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulne
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerab
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerabil
Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vuln
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is cau
Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability
Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability
Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vul
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability i
Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is c
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerabil
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerabi
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plu
Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel:
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started