In display, there is a possible use after free due to a race condition. This could lead to local escalation of privilege
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o
The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below ha
A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a reques
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an i
A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionalit
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bo
Frappe is a full-stack web application framework. Versions 14.99.5 and below and 15.0.0 through 15.80.1 include requests
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 ar
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa
vega-functions provides function implementations for the Vega expression language. Prior to version 6.1.1, for sites tha
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.
Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS
A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
A Denial of Service (DoS) vulnerability in evershop 2.1.0 and prior allows unauthenticated attackers to exhaust the appl
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211
An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 240
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions pri
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec
A malicious actor with access to the adjacent network could obtain unauthorized access to a UniFi Protect Camera by expl
A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p
An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder wit
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400,
Missing Authorization vulnerability in Marketing Fire LLC LoginWP - Pro allows Accessing Functionality Not Properly Cons
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in corourke iPhone We
Improper Validation of Specified Quantity in Input vulnerability in SaasProject Booking Package allows Accessing Functio
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc
An issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration a
Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sh
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This affects an unknown func
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KlbTheme Ma
A vulnerability was found in code-projects Online Product Reservation System 1.0. Impacted is an unknown function of the
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Missing Authorization vulnerability in codepeople Sell Downloads sell-downloads allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Confi
Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restauran
Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allo
Deserialization of Untrusted Data vulnerability in Themify Themify Edmin allows Object Injection.This issue affects Them
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started