An authenticated remote code execution vulnerability through undisclosed vectors exists in the BIG-IP and BIG-IQ Configu
When a classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Manageme
A vulnerability exists in BIG-IP systems where a highly privileged, authenticated attacker with at least the Resource Ad
On an HTTP/2 virtual server with Layer 7 DoS Protection configured, undisclosed traffic can result in an increase in mem
When BIG-IP PEM iRules are configured on a virtual server (iRules using commands starting with CLASSIFICATION::, CLASSIF
A vulnerability exists in an undisclosed BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker with
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
An authenticated attacker with the Resource Administrator or Administrator role can modify configuration objects through
When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processin
When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technolog
When a SIP profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (
When a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the apmd process to ter
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) comm
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the
A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with
When a BIG-IP is configured with DNS caching (Such as a DNS profile with caching enabled, SSL Orchestrator, Advanced WA
When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication,
U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administra
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the
An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iCon
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry fun
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipu
IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local a
Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inje
Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by
Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain a
Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbi
Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated atta
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote den
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia
An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allow
The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi
The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in
ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr par
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done u
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent
The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in al
Privilege escalation in the mk_mysql agent plugin on Windows in Checkmk <2.4.0p29, <2.3.0p47, and 2.2.0 (EOL) allows a l
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-ra
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blin
Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If the
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to tri
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi
After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started