Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Expr
The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec
Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algor
The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh
Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0
The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi
The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and
The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including,
The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1
Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to
WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator
xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative pr
xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system
CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authent
SPA-CART CMS 1.9.0.3 contains a stored cross-site scripting vulnerability in the product description parameter that allo
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all
In AzeoTech DAQFactory release 20.7 (Build 2555), an out-of-bounds write vulnerability can be exploited by an attacker t
In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by a
In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp
In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow
A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1
In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. Thi
In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This
In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co
In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp
In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea
In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea
In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could
In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check.
In WAVES_send_data_to_dsp of libaoc_waves.c, there is a possible out of bounds write due to a missing bounds check. This
In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect
In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap
In aocc_read of aoc_channel_dev.c, there is a possible double free due to improper locking. This could lead to local esc
In aoc_service_read_message of aoc_ipc_core.c, there is a possible out of bounds read due to improper input validation.
In PrepareWorkloadBuffers of gxp_main_actor.cc, there is a possible double fetch due to a race condition. This could lea
A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerabi
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevate
IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially craft
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow could an authenticated user to change the password of another us
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started