A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown process
A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of t
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the f
A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functiona
A vulnerability was detected in UTT HiPER 810G up to 1.7.7-171114. Affected by this vulnerability is the function strcpy
A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /b
A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_langu
A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the
A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /gof
A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the fil
A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/f
QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries throu
DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrie
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash th
eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows atta
ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers
ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers
AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' p
AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using
SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the applica
aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by ov
Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /gof
Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is n
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a denial of service (DoS) vuln
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerab
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/for
Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Comm
NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filen
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers o
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy o
A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpG
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templit
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a
calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows a
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append t
OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to befor
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 to befor
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUX
MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0.
REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Rev
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, an SQ
OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a cri
A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is a
Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configu
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started