A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function sub_3C6C0 of the file /goform/Q
A vulnerability has been found in Tenda F453 1.0.0.3. This affects the function fromwebExcptypemanFilter of the file /go
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown fu
A vulnerability was found in Wavlink WL-WN579X3-C 231124. This affects the function sub_40139C of the file /cgi-bin/fire
A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown functio
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an
A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown proc
A security vulnerability has been detected in H3C Magic B1 up to 100R004. Affected by this vulnerability is the function
A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform
A security flaw has been discovered in UTT HiPER 810G up to 1.7.7-171114. This impacts the function strcpy of the file /
A vulnerability was identified in UTT HiPER 810G up to 1.7.7-171114. This affects the function strcpy of the file /gofor
Crypt::Sodium::XS versions through 0.001000 for Perl has potential integer overflows. Combined aead encryption, combine
A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig
A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_
A vulnerability was identified in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function formQuickIndex of
A vulnerability was determined in Tenda FH451 1.0.0.9. Affected is the function sub_3C434 of the file /goform/AdvSetWan.
A vulnerability was found in Tenda FH451 1.0.0.9. This impacts the function fromSetCfm of the file /goform/setcfm. The m
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.
Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_r
Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7,
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /sessio
UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377
pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validat
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login
ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login
Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass v
ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exis
It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t
Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att
Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a
The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in
The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be
express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there
The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in a
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis
The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0
The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1
The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i
Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work
Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri
Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept
When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started