iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to 2.3.1.5, there is
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studi
StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_ap
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediatio
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint ret
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entr
Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untr
Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary c
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a netw
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a networ
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized att
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to exec
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to exe
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell co
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform che
A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exi
Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an ad
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate priv
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started