The Yoco Payments plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 3.9.0 via t
The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a
The MoneySpace plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dasinfomedia WPCHU
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team Woocommerc
Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Re
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote att
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Ni
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Ga
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vul
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shazdeh Hea
A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSave
DwyerOmega Isensix Advanced Remote Monitoring System (ARMS) 1.5.7 allows an attacker to retrieve sensitive information f
AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privilege
Sony BRAVIA Digital Signage 1.7.8 contains an information disclosure vulnerability that allows unauthenticated attackers
RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated at
iDS6 DSSPro Digital Signage System 6.2 contains an improper access control vulnerability that allows authenticated users
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote atta
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauth
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote atta
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows
Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5
Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass
The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below
An uncontrolled DLL loading path vulnerability exists in AsusSoftwareManagerAgent. A local attacker may influence the ap
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
In seninf, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile
In mminfra, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege i
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
In imgsys, there is a possible out of bounds write due to improper input validation. This could lead to local escalation
In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started