The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all vers
The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' p
Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elem
The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and in
The BlueSnap Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions
Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the
The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' param
The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripti
A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises
A State Pollution vulnerability was discovered in the TON Virtual Machine (TVM) before v2025.04. The issue exists in the
A Stack Overflow vulnerability was discovered in the TON Virtual Machine (TVM) before v2024.10. The vulnerability stems
A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User rol
The Starfish Review Generation & Marketing for WordPress plugin for WordPress is vulnerable to unauthorized modification
Calero VeraSMART versions prior to 2026 R1 contain hardcoded static AES encryption keys within Veramark.Framework.dll (V
Use after free in CSS in Google Chrome prior to 145.0.7632.75 allowed a remote attacker to execute arbitrary code inside
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a ma
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserial
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to 1.77.0, the local bl
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.5.1, the
BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0.rc3, a vulnerability
Cursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in ver
An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of
An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a den
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix inverted genmask check in
Authorization Bypass Through User-Controlled Key vulnerability in Universal Software Inc. FlexCity/Kiosk allows Exploita
Authentication Bypass Using an Alternate Path or Channel vulnerability in Universal Software Inc. FlexCity/Kiosk allows
Privilege Defined With Unsafe Actions, Missing Authentication for Critical Function vulnerability in Universal Software
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated s
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed u
WWW::OAuth 1.000 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptograp
ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode inte
Centova Cast 3.2.12 contains a denial of service vulnerability that allows attackers to overwhelm the system by repeated
iNetTools for iOS 8.20 contains a denial of service vulnerability in the Whois feature that allows attackers to crash th
SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to c
GHIA CamIP 1.2 for iOS contains a denial of service vulnerability in the password input field that allows attackers to c
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attac
PRO-7070 Hazır Profesyonel Web Sitesi version 1.0 contains an authentication bypass vulnerability in the administration
Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to
FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by
AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU regi
SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows atta
FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwrit
XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to
Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started