ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by
Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to
Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the
TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers t
SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers
SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers t
Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by o
Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the ap
GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by
APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the applicatio
KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling.
BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting
P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details thr
ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin p
An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api par
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage
Race in DevTools in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in spe
Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially
Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit
Use after free in CSS in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corr
A race condition vulnerability exists in MedusaJS Medusa v2.12.2 and earlier in the registerUsage() function of the prom
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary v
PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom oper
Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete
An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and
An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disabl
An issue was discovered in Pacom Unison Client 5.13.1. Authenticated users can inject malicious scripts in the Report Te
A missing authentication mechanism in the web management API components of Shenzhen Zhibotong Electronics ZBT WE2001 23.
MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The app
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and exp
A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially result
A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation pote
Improper input validation in AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentia
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt
ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that
Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potenti
Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration.
WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows loc
BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially e
The wpForo Forum plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.13
A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been repor
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started