Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions.
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w
The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil
attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authe
FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au
FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authe
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The I
A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown cod
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerabi
A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extensio
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. T
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shar
A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPP
A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/fo
A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiN
A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /si
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy al
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by re
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl.
A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown fun
A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /a
A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the
Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perfor
A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an un
A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unk
A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown pr
A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of
A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi
A vulnerability was identified in Wavlink WL-NU516U1-A M16U1_V240425. The impacted element is the function sub_407504 of
The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-
Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hit
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unkno
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the fi
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerabi
A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform
A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/
A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /gof
A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of t
A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the
A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/an
A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vuln
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started