Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa
Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/singl
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_up
Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint c
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbit
Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated using Perl's built-in r
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, data
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database ut
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_ti
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parame
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET paramete
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_re
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST paramete
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort a
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET pa
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GE
Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus bef
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local at
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification c
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attac
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileg
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vu
In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the me
In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in rem
In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM obje
In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to preven
In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against messag
In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fail
When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and u
ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a
A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started