Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke
jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a
Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff
A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U
An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a
A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the fil
A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting.
A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /
A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/
Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file
Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and sc
The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. Th
A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeComm
A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_41
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memo
jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_strin
simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of a
A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of
A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unk
Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php.
Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code ex
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the functi
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Re
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields.
Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search.
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServe
Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network
Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript
Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio
A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v
A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is som
A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t
Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a
A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Servi
An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows att
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cau
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate
In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp
In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broad
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started