The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including
The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due
A security vulnerability has been detected in Tenda F453 1.0.0.3. This impacts the function fromSafeEmailFilter of the f
A weakness has been identified in Tenda F453 1.0.0.3. This affects the function fromNatStaticSetting of the file /goform
A security flaw has been discovered in Tenda F453 1.0.0.3. The impacted element is the function formWebTypeLibrary of th
A vulnerability was identified in Tenda F453 1.0.0.3. The affected element is the function fromRouteStatic of the file /
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listi
A vulnerability was determined in Tenda F453 1.0.0.3. Impacted is the function fromSetWifiGusetBasic of the file /goform
A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the fil
A vulnerability has been found in itsourcecode Document Management System 1.0. Impacted is an unknown function of the fi
A flaw has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing of the f
A vulnerability was detected in itsourcecode College Management System 1.0. This vulnerability affects unknown code of t
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown funct
changedetection.io is a free open source web page change detection tool. In versions prior to 0.54.1, changedetection.io
Coturn is a free open source implementation of TURN and STUN Server. Coturn is commonly configured to block loopback and
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated SQL injection vulnerability
The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulne
tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's
Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `reada
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.2, an attacker who uses this vulnerability can cra
ADB Explorer is a fluent UI for ADB on Windows. In versions prior to Beta 0.9.26022, ADB-Explorer allows the `ManualAdbP
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.56 through 1.0.0-alpha.82, RustFS d
Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation le
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of t
A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function
A vulnerability has been found in itsourcecode Document Management System 1.0. This issue affects some unknown processin
Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implemen
Wasmtime is a runtime for WebAssembly. Starting with Wasmtime 39.0.0, the `component-model-async` feature became the def
Fiber is an Express inspired web framework written in Go. In versions on the v3 branch prior to 3.1.0, the use of the `f
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remo
Fiber is an Express inspired web framework written in Go. A denial of service vulnerability exists in Fiber v2 and v3 th
EventSentry versions prior to 6.0.1.20 contain an unverified password change vulnerability in the account management fun
SummaryThis advisory addresses a SQL injection vulnerability in the API endpoint used for retrieving contact activities.
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior expose RTSP streams without requirin
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulner
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged a
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could
Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this
Mastodon is a free, open-source social network server based on ActivityPub. FASP registration requires manual approval b
A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the abil
Multiple Finka programs use hard-coded Firebird database credentials (shared across all instances of this software). A m
Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the sec
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started