Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue
Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue a
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse
docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_orderopt.php component of GmbH Mecury Managed Print
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_markeralerts.php component of GmbH Mecury Managed Pr
A reflected cross-site scripted (XSS) vulnerability in the acc-menu_pricess.php component of GmbH Mecury Managed Print S
A reflected cross-site scripted (XSS) vulnerability in the dfm-menu_alerts.php component of GmbH Mecury Managed Print Se
A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or re
Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te
Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att
Due to a lack of user account state validation during authentication, locked user accounts can be successfully authentic
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when page
The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL quer
A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of th
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing trunc
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids. If the communication channel to the sta
Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files an
Argus Surveillance DVR 4.0 contains an unquoted service path vulnerability in the DVRWatchdog service that allows local
memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting
TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbi
WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to
Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation
ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows au
e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation pe
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary co
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handle
Opencart TMD Vendor System 3.x contains a blind SQL injection vulnerability that allows unauthenticated attackers to ext
A security vulnerability has been detected in EFM ipTIME A8004T 14.18.2. This vulnerability affects the function formWif
In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly,
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() f
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP serve
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, i
A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function i
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middlewa
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before versi
Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login en
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command executi
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET
pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started