Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 paramete
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. U
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a ma
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/
A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /gofo
A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/Portal
A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the f
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.
When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Rout
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths fo
Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server t
Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust
Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unval
Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the f
A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /gofo
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke
## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body
A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /
A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_se
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affect
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with
A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protoc
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_Ot
A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the
A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /A
A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unkno
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown fun
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unkno
WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attac
WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows
A security flaw has been discovered in Kushan2k student-management-system up to f16a4ceaddd6729c4b306ed4641cda3176c1ef2a
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown fu
A vulnerability was determined in USCiLab Cereal up to 1.3.2. Affected is an unknown function of the component Shared Po
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function ca
A flaw has been found in Boost Serialization up to 1.91. The impacted element is an unknown function. This manipulation
Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected b
A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerabil
A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-
A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the com
A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-ht
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started