A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /
A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the
A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file
Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstor
The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped,
Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to hand
Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig
Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t
Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsb
The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for
A flaw has been found in Belkin F9K1122 1.00.33. The affected element is the function formWISP5G of the file /goform/for
A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetN
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/c
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera
A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartCo
A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the f
WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/clo
WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vuln
A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit
A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform
A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the fil
A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextSha
FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local atta
Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local att
Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by
Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local a
MiniFtp contains a buffer overflow vulnerability in the parseconf_load_setting function that allows local attackers to e
JetAudio jetCast Server 2.0 contains a stack-based buffer overflow vulnerability in the Log Directory configuration fiel
Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows low-privilege users to execute arbitrary
Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers t
EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials
DVDXPlayer Pro 5.5 contains a local buffer overflow vulnerability with structured exception handling that allows local a
TuneClone 2.20 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers t
A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PR
A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processin
A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown proces
A vulnerability has been found in Tenda FH451 1.0.0.9. This vulnerability affects the function WrlclientSet of the file
A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet.
The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all ver
A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the c
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up
A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of th
i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL
ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL querie
phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbit
phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL quer
Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb
SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary
Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queri
Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by pro
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started