Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to
ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site
IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prio
Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limi
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f
OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial
Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with
Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent atta
Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configur
An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc
Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v
Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WC Lovers WCFM Mar
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a
LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut
Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacke
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via
In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or p
In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26
Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shel
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareS
Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Re
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea
@fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head
The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. Th
Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulne
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all
Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B
: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a
Uncontrolled Resource Consumption in Bosch VMS Central Server in Bosch VMS 12.0.1 allows attackers to consume excessiv
The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l
The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3
The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validat
An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric
Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr
It has been identified that a vulnerability (CWE-427) exists in the UPS (Uninterruptible Power Supply) management applic
radare2 prior to version 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function tha
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc
Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started