An SSTI (Server-Side Template Injection) vulnerability exists in the get_dunning_letter_text method of Frappe ERPNext th
An unauthenticated Broken Function Level Authorization (BFLA) vulnerability in Newgen OmniDocs v11.0 allows attackers to
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of
A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arb
FNT Command 13.4.0 is vulnerable to Directory Traversal.
FNT Command 13.4.0 is vulnerable to Code Execution via the C Base Module.
The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Attachment upl
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authenticated
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Unauthenticate
An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Uploaded attac
A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability a
A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an
Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerabil
In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR
The URL Shortify WordPress plugin before 1.11.4 does not sanitise and escape a parameter before outputting it back in t
The URL Shortify WordPress plugin before 1.11.3 does not sanitize and escape a parameter before outputting it back in t
A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshel
NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as
A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the
A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of th
A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown
A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of
A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing o
A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown func
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the c
A weakness has been identified in Tenda AC20 16.03.08.12. This affects the function httpd of the file /goform/openSchedW
A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer o
A vulnerability was identified in Tenda AC20 16.03.08.12. The affected element is the function formSetPPTPUserList of th
A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the fil
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of
A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakesho
A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown fun
A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /ad
A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown functio
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of
The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow becau
A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown functio
A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown funct
A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function o
A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file
A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects som
A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown
A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown proc
A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unkn
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the
A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started