An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv
Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr
The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnera
ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attack
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject a
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a
ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and
The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection vi
Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users
Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS
Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc
Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStr
Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipel
Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int
Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat
Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Serve
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write ca
Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unau
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5,
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5,
PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to
Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization
nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nn
basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when pa
Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbi
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path t
A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Su
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started