Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot:
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allow
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.
in OpenHarmony v6.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps.
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent
FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerabi
SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionalit
In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` cr
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch
Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authe
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /t
HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-suppli
Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an auth
ngrok v4.3.3 and 5.0.0-beta.2 is vulnerable to Command Injection.
In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations duri
An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive info
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n
The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowi
The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before usin
The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress
A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the func
A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the fi
A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetu
A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litem
A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the fil
A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of t
Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not ch
A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic
A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file
A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/fram
A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted elem
A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is th
Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract da
Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extr
Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated atta
Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities that allow at
WordPress Plugin WP with Spritz 1.0 contains a remote file inclusion vulnerability that allows unauthenticated attackers
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started