igmpproxy 0.4 before commit 2b30c36 allows remote attackers to cause a denial of service (application crash) via a craft
A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /
A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk
A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio
Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System al
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthe
Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Di
The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par
A heap-based buffer overflow vulnerability exists in the PDF parsing of Foxit PDF Reader when processing specially craft
A use-after-free vulnerability exists in the annotation handling of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1
A use-after-free vulnerability exists in the PDF file parsing of Foxit PDF Reader before 2025.2.1, 14.0.1, and 13.2.1 on
A use-after-free vulnerability exists in the AcroForm handling of Foxit PDF Reader and Foxit PDF Editor before 2025.2.1,
The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-S
The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic.
A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15
Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially craft
A local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installat
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauth
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience all
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
rofl0r/proxychains-ng versions up to and including 4.17 and prior to commit cc005b7 contain a stack-based buffer overflo
merbanan/rtl_433 versions up to and including 25.02 and prior to commit 25e47f8 contain a stack-based buffer overflow vu
An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project thro
An insecure deserialization vulnerability exists in the download.php script of the to3k Twittodon application through co
BullWall Server Intrusion Protection (SIP) services are initialized after login services during system startup. A local,
BullWall Server Intrusion Protection has a noticeable configuration-dependent delay before the MFA check for RDP connect
BullWall Ransomware Containment supports configurable file and directory exclusions such as '$RECYCLE.BIN' to balance mo
BullWall Ransomware Containment may not always detect an encrypted file. This issue affects a specific file inspection m
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.
File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious
Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system comma
Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32
A denial of service vulnerability in Kentico Xperience allows attackers to launch DoS attacks via specially crafted requ
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via
A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through exi
A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via onli
An access control bypass vulnerability in Kentico Xperience allows administrators to modify global administrator user pr
An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions t
MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.
A denial-of-service vulnerability exists in the omec-project UPF (pfcpiface component) in version upf-epc-pfcpiface:2.1.
A denial-of-service vulnerability exists in the omec-upf (upf-epc-pfcpiface) in version upf-epc-pfcpiface:2.1.3-dev. Whe
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started