Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, B
CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fa
CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonica
CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers
CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config f
CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attacker
CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerabi
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool,
CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to p
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/sr
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox a
MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames cor
CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula chara
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (age
Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: fro
Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.
Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.
Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.
Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions.
Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions.
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLH
Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernet
Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started