IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ
Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an
The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation FREQSHIP-mini for Windows versions 8.0.0
A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr
Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute mali
Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService th
GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentia
Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorServic
Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary
NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows loc
Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Servic
BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to poten
ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local at
Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attac
TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows loca
NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configur
Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attacker
Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path
Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a
Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer o
Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists i
jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, spe
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to
OpenSlides is a free, web based presentation and assembly system for managing and projecting agenda, motions and electio
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a
Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur
Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue aff
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr
Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a
OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the
melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacke
Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker
melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker
Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apol
Water-Melon Melon commit 9df9292 and below is vulnerable to Denial of Service. The HTTP component doesn't have any maxim
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started