Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultima
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAt
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command a
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerabi
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12,
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPending
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plug
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`),
SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, Dire
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas
Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.
Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.
Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.
ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing att
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted devi
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.
Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.
Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.
Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.
Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.
Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.
Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut
A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_
Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 1
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, T
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.
Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fi
Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb
Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firef
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1,
Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox
Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started