Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allo
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web
A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via craft
IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue. This can be exploited only
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An
telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service creden
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an a
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables re
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromAddressNat of the file /goform/addre
A security flaw has been discovered in Tenda F453 1.0.0.3. Affected by this issue is the function frmL7ProtForm of the f
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker t
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated atta
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in EFM-Networks, Inc. IpTIME T5008, EFM-Network
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of t
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke
A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the auth
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attac
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacke
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attack
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker
A vulnerability was determined in Tenda F453 1.0.0.3. Affected is the function fromDhcpListClient of the file /goform/Dh
A vulnerability was found in Tenda F453 1.0.0.3. This impacts the function fromP2pListFilter of the file /goform/P2pList
Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen
Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started