Net-Billetterie 2.9 contains an SQL injection vulnerability in the login parameter of login.inc.php that allows unauthen
Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit
Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitr
EverSync 0.5 contains an arbitrary file download vulnerability that allows unauthenticated attackers to access sensitive
BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri
Warranty Tracking System 11.06.3 contains an SQL injection vulnerability that allows attackers to execute arbitrary SQL
The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configur
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version
SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b
changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f
OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve
Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS
Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained
Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memca
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header
Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner
Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability all
Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V
A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the
A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/
Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec
Denial of service due to insufficient input validation in authentication logging. The following products are affected: A
Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec
Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are a
Payment Orchestrator Service Elevation of Privilege Vulnerability
OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst
OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintend
OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc
OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control
OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started