CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submi
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a
The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2.
The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,
The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '
The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c
The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,
The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5
The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all
The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedF
The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc
The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in
The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versi
The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe
OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair
OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system
OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers wi
OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, al
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device ide
The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter name
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthe
WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does
Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to cra
A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport t
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr
SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can per
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupporte
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS
Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator p
Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applicati
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content bein
A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated r
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL u
ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading
DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side T
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started