When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida
After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica
The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete
When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie
The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use
After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the
When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under
A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by
Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b
Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t
Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the
The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a
The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be
The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t
Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa
Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the
The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers
The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the
The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,
The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v
The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu
The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri
DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass
FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,
FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f
The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb
The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al
FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s
Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2,
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30
HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeU
An improper access check allows unauthorized users to create custom fields via webservices endpoints.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started