Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This
Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulne
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?met
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted elemen
jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBui
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue
Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the
Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorizati
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can coll
A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown fun
Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handleb
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching lan
lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.def
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-b
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-chec
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improp
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an impro
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper p
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-ch
A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown func
@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary J
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administ
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authentica
A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP
Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.
Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.
Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.
Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started