Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior do not implement rate limiting or accoun
Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 store a user password in a client-side c
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior use RC4 with a hard-coded key embedded i
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext withi
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerabilit
Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to mod
WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a
Actual is a local-first personal finance tool. Prior to version 26.2.1, missing authentication middleware in the ActualB
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a p
TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI read
Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
Information disclosure due to uninitialized memory in Firefox and Firefox Focus for Android. This vulnerability was fixe
Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed i
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fir
A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of
A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of direc
IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is on
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows,
DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arb
When the "Silent Just-In-Time Provisioning" feature is enabled for a federated identity provider (IDP) there is a risk
The Responsive Lightbox & Gallery WordPress plugin before 2.6.1 is vulnerable to an Unauthenticated Stored-XSS attack du
A security vulnerability has been detected in itsourcecode Document Management System 1.0. Affected is an unknown functi
A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the f
yt-dlp is a command-line audio/video downloader. Starting in version 2023.06.21 and prior to version 2026.02.21, when yt
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG362
A post-authentication command injection vulnerability in the log file download function of the Zyxel EX3301-T0 firmware
A vulnerability was determined in DataLinkDC dinky up to 1.2.5. This affects the function addInterceptors of the file di
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. Thi
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `code
Astro is a web framework. Prior to version 9.5.4, Server-Side Rendered pages that return an error with a prerendered cus
free5GC SMF provides Session Management Function for free5GC, an open-source project for 5th generation (5G) mobile core
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A vulnerability has been found in Tenda AC8 16.03.34.06. This affects the function webCgiGetUploadFile of the file /cgi-
A vulnerability was detected in itsourcecode Event Management System 1.0. The affected element is an unknown function of
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co
free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticat
free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of fr
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started