MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized user
EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries i
berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to man
TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumer
The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attack
Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipul
Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application
The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0
Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut
The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a
A weakness has been identified in itsourcecode School Management System 1.0. The affected element is an unknown function
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color
Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnera
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, permali
A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of t
A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Adm
An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denia
An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn
Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria
Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p
Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsin
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issu
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This
OpenProject is an open-source, web-based project management software. To enable the real time collaboration on documents
Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupa
Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, some su
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, does not properly validate TLS ce
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the L
An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via
A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to
A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memor
NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an in
NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacke
NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successfu
SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that a
Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration par
PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system file
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions b
docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to ex
Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthentica
WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to b
aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by ove
OpenProject is an open-source, web-based project management software. Versions prior to 16.6.6 and 17.0.2 have an arbitr
EGroupware is a Web based groupware server written in PHP. A SQL Injection vulnerability exists in the core components o
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started