PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows
PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that all
PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers t
Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to
Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows
Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of
A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket pr
Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable lo
Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote us
WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows u
OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers t
qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information b
Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated
KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_ite
ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL comma
Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication b
Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate
SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting S
School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows at
Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticat
Wecodex Restaurant CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate d
Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authenti
The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh
In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths i
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the functio
A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /
A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonR
A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the f
Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a por
On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an
When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is pa
The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installat
The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a use
A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processin
A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unkn
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil
A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTo
The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP hea
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includ
A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file
A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the fil
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the '
An OS command injection vulnerability in the web management interface of certain ASUS router models allows remote authen
The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6
Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, the `repla
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's
Saloon is a PHP library that gives users tools to build API integrations and SDKs. Prior to version 4.0.0, when building
Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetim
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started