Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO pro
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser
IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to
SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output m
App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ac
App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th
An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with
An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with f
An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/
An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W wi
Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr
This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a min
In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavi
Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules).
Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report
n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy My
Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont
n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n
FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to
Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST,
Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A
Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
Tanium addressed a denial of service vulnerability in Tanium Server.
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe
The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve
The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure
A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc
A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers auth
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re
When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi
There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,
When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio
The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper
When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi
After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object
The application re-enters the document structure via field processing and deletes the current page, and then continues u
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started