Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to pot
Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users
Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary
NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated pa
VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by ma
Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t
CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attacke
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse
Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows atta
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse
GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of Internatio
Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Modeler versions 1.22.4 and earlier are affected by an out-of-bounds write vulnerability that could result
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking Virtual Intranet Access (VIA)
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw i
Substance3D - Designer versions 15.0.3 and earlier are affected by an out-of-bounds write vulnerability that could resul
Substance3D - Sampler versions 5.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Painter versions 11.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result
Substance3D - Stager versions 3.1.5 and earlier are affected by a Use After Free vulnerability that could result in arbi
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, AES/CBC/PKCS5Padding
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses java.uti
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, the salt is derived
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses padLeft(
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses determin
Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Enc
Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either A
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors run
An improper input handling vulnerability exists in the web-based management interface of mobility conductors running eit
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exp
Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
Bridge versions 15.1.2, 16.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in
InCopy versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in
Illustrator versions 29.8.3, 30.0 and earlier are affected by an Untrusted Search Path vulnerability that could result i
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that
InDesign Desktop versions 21.0, 19.5.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that
Dreamweaver Desktop versions 21.6 and earlier are affected by an Incorrect Authorization vulnerability that could result
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could lead
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Input Validation vulnerability that could resu
Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started