Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacke
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nel
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This iss
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yoren Chang Media
Missing Authorization vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows Exploit
Deserialization of Untrusted Data vulnerability in codetipi Valenti valenti allows Object Injection.This issue affects V
Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constra
Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Obj
A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown funct
A flaw has been found in itsourcecode Event Management System 1.0. Affected by this vulnerability is an unknown function
A vulnerability was detected in itsourcecode Event Management System 1.0. Affected is an unknown function of the file /a
OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh
The Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin plugin for WordPress is vulnerable
The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc
The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca
The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala
The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of data
The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param
The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i
The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin inst
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to
The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is
The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version
The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch
A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted ele
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions
A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-b
Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit
Integer overflow in V8 in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap co
Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of b
Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute a
MajorDoMo (aka Major Domestic Module) allows unauthenticated arbitrary module uninstallation through the market module.
MajorDoMo (aka Major Domestic Module) contains an unauthenticated SQL injection vulnerability in the commands module. Th
MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability through method paramete
MajorDoMo (aka Major Domestic Module) contains a stored cross-site scripting (XSS) vulnerability via the /objects/?op=se
Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the a
SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL st
FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by ma
Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username fie
gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by m
iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overfl
Foscam Video Management System 1.1.4.9 contains a denial of service vulnerability in the username input field that allow
Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system
Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary sys
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started