Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vu
After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a s
CAI Content Credentials versions [email protected], c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a D
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a S
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an
A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow a
A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacke
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacke
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggeri
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certa
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers t
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul
Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul
A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attack
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remot
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u
Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 fil
Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker
ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t
AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli
changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o
Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Xibo is an open source digital signage platform with a web content management system and Windows display player software
changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and
External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose inf
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started