Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from
NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued conn
Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from U
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Matterm
A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts
HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or
The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring
HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, conta
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux,
TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP hea
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function
TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validati
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load sta
The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding th
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 expos
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an un
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Cli
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of
A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bach
HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown proc
HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to intr
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown c
Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.
Unauthenticated Local File Inclusion in Måne <= 1.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.
Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS,
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the fi
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown f
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started