Memory corruption while loading an invalid firmware in boot loader.
Memory corruption while handling concurrent memory mapping and unmapping requests from a user-space application.
Memory corruption while routing GPR packets between user and root when handling large data packet.
Memory corruption while handling IOCTL calls to set mode.
Memory corruption while copying packets received from unix clients.
Memory corruption while processing MFC channel configuration during music playback.
Memory corruption during video playback when video session open fails with time out error.
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the ani
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML sty
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads Mo
Zed, a code editor, has an aribtrary code execution vulnerability in versions prior to 0.218.2-pre. The Zed IDE loads La
Storybook is a frontend workshop for building user interface components and pages in isolation. A vulnerability present
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram
In mcp-server-git versions prior to 2025.12.17, the git_diff and git_checkout functions passed user-controlled arguments
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensiti
A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious
ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to do
phpMyFAQ 3.1.12 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into
UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to uplo
Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in
HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access rol
ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas in
ChurchCRM is an open-source church management system. A SQL Injection vulnerability exists in the legacy endpoint `/Repo
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, a SQL injection vulnerability exists i
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 have a SQL injection vulnerability in the
A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged use
Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macO
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and
RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT)
ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reload
ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th
AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata in
AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Response
AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permi
AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The
AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a
Incorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via d
CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary co
ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in th
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside t
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside th
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started