A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulne
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote
A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in s
A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Net
A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vu
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to es
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() v
An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escal
The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access p
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the lu
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePunch Slider
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.
Unauthenticated Cross Site Scripting (XSS) in Timetics <= 1.0.58 versions.
Unauthenticated Cross Site Scripting (XSS) in Optimole <= 4.2.7 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions.
Unauthenticated Cross Site Scripting (XSS) in perfmatters <= 2.6.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Modula - PRO <= 2.10.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in eCommerce Product Catalog <= 3.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in ReviewX <= 2.3.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Customize My Account for WooCommerce <= 4.3.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Search Atlas SEO <= 2.6.6 versions.
Unauthenticated Cross Site Scripting (XSS) in MC Woocommerce Wishlist <= 1.9.19 versions.
Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started