FlexRIC v2.0.0 crashes when receiving a duplicate E2_SETUP_REQUEST from the same or spoofed E2 Node. The iApp registry e
FlexRIC v2.0.0 contains a reachable assertion in the iApp message dispatcher. The dispatcher validates incoming E2AP mes
FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote
A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBui
A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /http
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious
Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPre
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Stat
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf al
FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pendi
FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a
A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown fun
A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /l
A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/applicatio
A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file
A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobile
Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co
A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the fil
A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown funct
A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown functi
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an
A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function
A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maxi
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from
Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receiv
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user wit
A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstance
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe
Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploit
Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlie
A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of
A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown pr
It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches
A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff94443
A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1.
A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authe
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proxi
A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function
A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skil
A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the f
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started