Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in th
Gophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, da
A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown fun
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This im
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an e
JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privi
SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local user
TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate databas
Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows loca
thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries th
RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers t
BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service tha
Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potenti
Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local at
A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown func
Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rend
A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/s
A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of t
A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the fi
A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown functio
A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of
UAF concurrency vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect a
Out-of-bounds write vulnerability in the camera module. Impact: Successful exploitation of this vulnerability may affect
Heap-based buffer overflow vulnerability in the image module. Impact: Successful exploitation of this vulnerability may
The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all ver
Access control settings for forum post custom fields are not applied to the JSON output type, leading to an ACL violatio
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Function Information Disclosure Vulnerability
Tanium addressed an improper input validation vulnerability in Deploy.
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
pgAdmin versions 9.11 are affected by a Restore restriction bypass via key disclosure vulnerability that occurs when run
An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on
Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin. The application relies o
Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, w
Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An
ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application
10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that all
Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the applica
ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers
UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by man
UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allow
Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated adm
Axigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability i
Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegat
phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter th
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started