Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.
An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose e
U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T
A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concur
Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI h
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireles
This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Clic
The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including
Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This
Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege
Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicio
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local f
In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting pri
In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c Th
NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Mani
Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associa
As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers.
When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe
When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a
An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t
TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitra
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. Thi
All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image
A flaw has been found in Tenda 4G300 US_4G300V1.0Mt_V1.01.42_CN_TDC01. Affected is the function sub_427C3C of the file /
A security vulnerability has been detected in 1024-lab smart-admin up to 3.30.0. This affects an unknown function of the
A vulnerability was detected in VetCoders mcp-server-semgrep 1.0.0. This affects the function analyze_results/filter_res
A weakness has been identified in BurtTheCoder mcp-dnstwist up to 1.0.4. Affected by this vulnerability is the function
A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of th
A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of
A vulnerability was determined in UTT HiPER 1250GW up to 3.2.7-210907-180535. This vulnerability affects the function st
A vulnerability was found in Algovate xhs-mcp 0.8.11. This affects the function xhs_publish_content of the file src/serv
A vulnerability was found in PolarVista xcode-mcp-server 1.0.0. This issue affects the function build_project/run_tests
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_p
A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of th
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V
A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection en
Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrar
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attacke
MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malici
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated us
SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers
Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that
Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that a
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started