clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/c
A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan
A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the func
Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi
The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vuln
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in al
The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version
MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where
Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom ren
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generatin
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT
A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper val
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL w
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFi
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), a
Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block
Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not val
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting i
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-ma
TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC in
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.
An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Serv
A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file n
A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown functi
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that thi
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerab
A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979
Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrar
Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious
Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that a
An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A cli
A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multipl
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple Sync
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-siz
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers
A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multip
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the
Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an
Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive infor
Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started