Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the security parameter of the sub_4C408 function. T
Tenda AX-1806 v1.0.0.1 was discovered to contain a stack overflow in the timeZone parameter of the fromSetSysTime functi
User provided uploads to the Easy Discuss component for Joomla aren't properly validated. Uploads are purely checked by
SteelSeries Nahimic 3 1.10.7 allows Directory traversal.
In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered wit
TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into t
The Librarian `supervisord` status page can be retrieved by the `web_fetch` tool, which can be used to retrieve running
The Librarian contains an internal port scanning vulnerability, facilitated by the `web_fetch` tool, which can be used w
The Librarian contains a information leakage vulnerability through the `web_fetch` tool, which can be used to retrieve a
Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Abi
In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy U
In Apache Airflow versions before 3.1.6, when rendered template fields in a Dag exceed [core] max_templated_field_length
HCL MyXalytics is affected by improper management of a static JWT signing secret in the web application, where the secr
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up
OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, whic
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can up
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can up
Delta Electronics DIAView has Command Injection vulnerability.
The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl
Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remot
Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimizatio
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed O
The Process Optimization application suite leverages connection channels/protocols that by-default are not encrypted an
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Process Optim
The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Standard User) to tamper
Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to
NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing
Backup Key Recovery 2.2.7 contains a denial of service vulnerability that allows attackers to crash the application by o
WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attack
Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that
Sync Breeze 13.6.18 contains an unquoted service path vulnerability in its Windows service configuration that allows loc
Dup Scout 13.5.28 contains an unquoted service path vulnerability in its Windows service configuration that allows local
Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows loca
Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with Lo
iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attacke
Vianeos OctoPUS 5 contains a time-based blind SQL injection vulnerability in the 'login_user' parameter during authentic
Leawo Prof. Media 11.0.0.1 contains a denial of service vulnerability that allows attackers to crash the application by
ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FT
Telegram Desktop 2.9.2 contains a denial of service vulnerability that allows attackers to crash the application by send
Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code
SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the applic
Active WebCam 11.5 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code
Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash t
WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editin
TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem pri
Redragon Gaming Mouse driver contains a kernel-level vulnerability that allows attackers to trigger a denial of service
Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remot
Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrar
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started