PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs h
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application enable
Hollo is a federated single-user microblogging software designed to be federated through ActivityPub. Prior to 0.6.20 an
ZAI Shell is an autonomous SysOps agent designed to navigate, repair, and secure complex environments. Prior to 9.0.3, t
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener acc
Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Supe
Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig f
Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex
FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthe
A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target ema
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verif
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can p
FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a lo
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, audin_server_recv_formats frees an inc
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completion
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, sdl_Pointer_New frees data on failure,
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, A capture thread sends sample response
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the a
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the devi
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can send client notificati
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerabili
Crafted delegations or IP fragments can poison cached delegations in Recursor.
Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd
Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Au
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admi
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Infor
C&Cm@il developed by HGiga has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbit
A security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some u
An unauthenticated remote attacker can bypass authentication by exploiting insufficient URI validation and using path tr
A security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the
A vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file
MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability. Due to the MacroHub application launching
A vulnerability was found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of th
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports old SSL
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product supports weak cr
A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown func
A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Admi
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_f
A flaw has been found in Tenda AC8 16.03.33.05. Affected by this vulnerability is an unknown functionality of the file /
A vulnerability was detected in Tenda AC8 16.03.33.05. Affected is the function fromSetWifiGusetBasic of the file /gofor
A security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown func
A vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function
A vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file
A vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the
A vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of t
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started