In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-serve
ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv
ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via QueryView.php with th
ChurchCRM is an open-source church management system. Prior to 7.1.0, the application is vulnerable to time-based SQL in
ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in PropertyTy
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-suppl
ChurchCRM is an open-source church management system. Prior to 7.1.0, a reflected Cross-Site Scripting (XSS) vulnerabili
ChurchCRM is an open-source church management system. Prior to 7.1.0, an authenticated API user can modify any family re
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was identified in /
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, an SQL injection vulnerability was found in the en
ChurchCRM is an open-source church management system. Prior to 7.1.0, a second order SQL injection vulnerability was fou
ChurchCRM is an open-source church management system. Versions prior to 7.1.0 have an SQL injection vulnerability in the
ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability
ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnera
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a server crash by sending a malfor
NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exp
NVIDIA Triton Inference Server contains a vulnerability where insufficient input validation and a large number of output
OpenHarness prior to commit 166fcfe contains an improper access control vulnerability in built-in file tools due to inco
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not
SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. In 5.2.5188 and earlier, a pre-authenticatio
PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded
PraisonAI is a multi-agent teams system. Prior to 1.5.113, The PraisonAI templates installation feature is vulnerable to
PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-contr
PraisonAI is a multi-agent teams system. Prior to 1.5.113, _validate_path() calls os.path.normpath() first, which collap
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3
PolarLearn is a free and open-source learning program. In 0-PRERELEASE-14 and earlier, setCustomPassword(userId, passwor
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
Emissary is a P2P based data-driven workflow engine. Prior to 8.39.0, the Executrix utility class constructed shell comm
ChurchCRM is an open-source church management system. Prior to 6.5.3, a stored Cross-Site Scripting (XSS) vulnerability
Strawberry GraphQL is a library for creating GraphQL APIs. Strawberry up until version 0.312.3 is vulnerable to an authe
Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with only
Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operat
A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secur
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists
Strawberry GraphQL is a library for creating GraphQL APIs. Prior to 0.312.3, Strawberry GraphQL's WebSocket subscription
FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started