Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input valida
Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command
Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command
Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog
Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Win
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authen
Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telne
A vulnerability was identified in Tenda AC21 16.03.08.16. The affected element is the function fromAdvSetMacMtuWan of th
PolarLearn is a free and open-source learning program. Prior to version 0-PRERELEASE-15, the vote API route (`POST /api/
Runtipi is a personal homeserver orchestrator. Starting in version 4.5.0 and prior to version 4.7.2, an unauthenticated
gradle-completion provides Bash and Zsh completion support for Gradle. A command injection vulnerability was found in gr
tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions up to and includin
Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li
TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass
An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to in
A Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactica
A stack overflow in the mk_http_index_lookup function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to
An out-of-bounds read in the mk_mimetype_find function (mk_server/mk_mimetype.c) of monkey commit f37e984 allows attacke
An out-of-bounds read in the header_cmp function (mk_server/mk_http_parser.c) of monkey commit f37e984 allows attackers
A NULL pointer dereference in the mk_http_range_parse function (mk_server/mk_http.c) of monkey commit f37e984 allows att
An out-of-bounds read in the mk_vhost_fdt_close function (mk_server/mk_vhost.c) of monkey commit f37e984 allows attacker
A use-after-free in the mk_http_request_end function (mk_server/mk_http.c) of monkey commit f37e984 allows attackers to
A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers t
An out-of-bounds read in the mk_ptr_to_buf in mk_core function (mk_memory.c) of monkey commit f37e984 allows attackers t
An out-of-bounds read in the http_parser_transfer_encoding_chunked function (mk_server/mk_http_parser.c) of monkey commi
A vulnerability was found in Tenda AX12 Pro V2 16.03.49.24_cn. Affected by this issue is some unknown functionality of t
An authenticated buffer handling flaw in TP-Link VIGI C385 V1 Web API lacking input sanitization, may allow memory corru
A weakness in the web interface’s application layer encryption in VX800v v1.0 allows an adjacent attacker to brute force
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escal
A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /ad
Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.
A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some
A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unkno
A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the fil
A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the fil
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Inte
10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local a
SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by
CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary
BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with eleva
The Ruijie Networks Switch eWeb S29_RGOS version 11.4 contains a directory traversal vulnerability that allows unauthent
Audio Playback Recorder 3.2.2 contains a local buffer overflow vulnerability in the eject and registration parameters th
Gnome Fonts Viewer 3.34.0 contains a heap corruption vulnerability that allows attackers to trigger an out-of-bounds wri
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started