The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to,
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers
A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the fi
A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the fu
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cro
Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the
Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibl
Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creati
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform perm
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability.
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `o
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint pas
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" p
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermissio
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` metho
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`AP
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr
cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions
strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allo
A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz
A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy
A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables
Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600
Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600
A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php`
A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows atta
A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allo
A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner compo
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoi
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L
cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `p
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` en
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` functi
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AV
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.ph
Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.0
An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s a
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started