DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute ar
BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute
SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary cod
Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users
Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows
Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows l
Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execut
Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL c
PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated
Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modul
The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: prevent pcp corruption with SMP=n T
HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all
Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulat
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database informat
Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attacke
Frigate 3.36.0.9 contains a local buffer overflow vulnerability in the Command Line input field that allows attackers to
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the 'Find Computer' feature that allows
OpenCTI 3.3.1 is vulnerable to a directory traversal attack via the static/css endpoint. An unauthenticated attacker can
Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by craf
Frigate 2.02 contains a denial of service vulnerability that allows attackers to crash the application by sending oversi
Code Blocks 20.03 contains a denial of service vulnerability that allows attackers to crash the application by manipulat
RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to ex
e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to
HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries thr
Wing FTP Server 6.3.8 contains a remote code execution vulnerability in its Lua-based web console that allows authentica
Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary co
FTPDummy 4.80 contains a local buffer overflow vulnerability in its preference file handling that allows attackers to ex
Socusoft Photo to Video Converter Professional 8.07 contains a local buffer overflow vulnerability in the 'Output Folder
Port Forwarding Wizard 4.8.0 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary c
Nidesoft DVD Ripper 5.2.18 contains a local buffer overflow vulnerability in the License Code registration parameter tha
Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension rest
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.
IBM Db2 for Windows 12.1.0 - 12.1.3 could allow a local user with filesystem access to escalate their privileges due to
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 could allow an instance owner to execu
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote
SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_po
Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by
A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown
A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function che
Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows atta
Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentia
Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration.
Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arb
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in endpoint `/PaddleNumEditor
A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an u
A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the
A security flaw has been discovered in Totolink A3600R 5.9c.4959. This issue affects the function setAppEasyWizardConfig
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started