CoreShop is a Pimcore enhanced eCommerce solution. In versions 5.0.1 through 5.1.0-beta.1,, the GitHub Actions workflow
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned
Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does n
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti
Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-pri
nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured No
An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and
The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not
Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could
Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method t
Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked fo
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing
An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUp
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_e
bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial o
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted fr
HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak co
Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo
WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenti
LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary co
AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structur
NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attacker
PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary
Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ
Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL
All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro
A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site script
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user t
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain admini
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "
HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::E
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started