A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, th
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user accoun
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attack
A command injection vulnerability has been reported to affect Media Streaming add-on. If an attacker gains local network
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 1
Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pr
The 'Videospirecore Theme Plugin' plugin for WordPress is vulnerable to privilege escalation via account takeover in all
The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information S
The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Paramet
Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Applicati
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cl
The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin
The affected products are vulnerable to an uncaught exception that could allow an unauthenticated attacker to remotely c
Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ar
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can
DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resul
DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr
Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could re
Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arb
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a craft
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i
Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result i
Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i
SiYuan is a personal knowledge management system. Prior to 3.5.5, the /api/file/getFile endpoint uses case-sensitive str
Worklenz is a project management tool. Prior to 2.1.7, there are multiple SQL injection vulnerabilities were discovered
ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #40, a Time-of-Check to Time-of-Use (TOCTOU) ra
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.
Emmett is a framework designed to simplify your development process. Prior to 1.3.11, the cookies property in mmett_core
Docmost is open-source collaborative wiki and documentation software. From 0.20.0 and before 0.25.0, the public share pa
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacke
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to e
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthor
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a net
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a networ
Improper authentication in Windows Storage allows an authorized attacker to elevate privileges locally.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started