A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of th
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions a
A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp o
A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp
A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp o
A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/de
A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the
A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.cla
A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by th
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file so
The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to,
CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving d
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feat
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was ide
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could wri
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to mem
In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a
In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted
In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to imprope
Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof
Disk Sorter Server 13.6.12 contains an unquoted service path vulnerability in its binary path configuration that allows
Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows
StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts
Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payload
Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts i
Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads
Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payl
Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads
WifiHotSpot 1.0.0.0 contains an unquoted service path vulnerability in its WifiHotSpotService.exe that allows local atta
Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowin
DHCP Broadband 4.1.0.1503 contains an unquoted service path vulnerability in its service configuration that allows local
BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers c
WebSSH for iOS 14.16.10 contains a denial of service vulnerability in the mashREPL tool that allows attackers to crash t
Acer Backup Manager 3.0.0.99 contains an unquoted service path vulnerability in the NTI IScheduleSvc service that allows
Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code
iDailyDiary 4.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowin
Acer ePowerSvc 6.0.3008.0 contains an unquoted service path vulnerability that allows local users to potentially execute
DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows lo
RarmaRadio 2.72.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowi
DupTerminator 1.4.5639.37199 contains a denial of service vulnerability that allows attackers to crash the application b
Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web
In MIT Kerberos 5 (aka krb5) before 1.22 (with incremental propagation), there is an integer overflow for a large update
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1
Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to
RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signat
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started