Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env
Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code
A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of t
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permissio
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impe
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to e
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Int
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to
IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mut
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin
IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A
FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra
FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an
Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel
Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conver
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored c
FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored c
NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free
NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful ex
NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A s
NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improp
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds writ
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between n
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use iss
NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex
A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Th
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed
FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w
FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer alloc
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path
Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-o
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerabili
NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A s
NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started