A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. Impacted is an unknow
A security flaw has been discovered in code-projects Online Product Reservation System 1.0. This vulnerability affects u
In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noex
In the Linux kernel, the following vulnerability has been resolved: hfs: fix potential use after free in hfs_correct_ne
In the Linux kernel, the following vulnerability has been resolved: ALSA: firewire-motu: add bounds check in put_user l
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Imp
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.ses
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has an Arbitrary File Upload vulnerability, allowing aut
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/C
A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/fo
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpC
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of
The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL stat
A vulnerability was determined in bg5sbk MiniCMS up to 1.8. This affects an unknown function of the file /mc-admin/post-
A vulnerability was found in bg5sbk MiniCMS up to 1.8. The impacted element is an unknown function of the file /minicms/
A vulnerability has been found in bg5sbk MiniCMS up to 1.8. The affected element is an unknown function of the file /mc-
A vulnerability was found in code-projects Online Product Reservation System 1.0. This affects an unknown part of the fi
A vulnerability has been found in code-projects Online Product Reservation System 1.0. Affected by this issue is some un
A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of
A security vulnerability has been detected in code-projects Online Product Reservation System 1.0. This impacts an unkno
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an improper access control vulnerability that allows u
Petlibro Smart Pet Feeder Platform versions up to 1.7.31 contains an authorization bypass vulnerability that allows unau
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Ene
MessagePack for Java is a serializer implementation for Java. A denial-of-service vulnerability exists in versions prior
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagist
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template in
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulne
Emlog is an open source website building system. Versions up to and including 2.5.19 are vulnerable to server-side Out-o
A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend
A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Fro
A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /F
A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit
An issue in Vatilon v1.12.37-20240124 allows attackers to access sensitive directories and files via a directory travers
Vatilon v1.12.37-20240124 was discovered to transmit user credentials in plaintext.
An authentication bypass in the /cgi-bin/jvsweb.cgi endpoint of Revotech I6032W-FHW v1.0.0014 - 20210517 allows attacker
An exposure of sensitive system information to an unauthorized control sphere vulnerability has been reported to affect
An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to com
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attac
A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerabil
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker
A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processin
A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the f
A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /wor
A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksh
A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The mani
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started