Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi All In
Stack-based buffer overflow vulnerability exists in SEIKO EPSON Web Config. Specially crafted data input by a logged-in
An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary me
CHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper check for unusual or exceptional conditions. If a rem
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote
An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP op
ChurchCRM is an open-source church management system. Prior to version 6.5.0, a SQL injection vulnerability exists in th
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 had a bypass caused by `pty` missi
Fickling is a Python pickling decompiler and static analyzer. Versions prior to 0.1.6 are missing `marshal` and `types`
The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manage
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authentica
A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulner
A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulner
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabili
A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerab
A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vu
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerabi
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerabi
A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerab
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `lan
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulne
AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne
AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne
AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne
A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnera
AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulne
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi
A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force a Memory corruption vulnerabi
AA maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vul
A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read v
AA maliciously crafted X_T file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnera
A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vu
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and
Blackcat CMS 1.4 contains a remote code execution vulnerability that allows authenticated administrators to upload malic
Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrar
Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arb
Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that all
Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP file
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject sys
ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manip
GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows att
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload m
An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account
An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a m
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext/acc
An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_documents() at erpnext.acc
A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 Print Format renderin
An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext throug
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. Th
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started