An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged
Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.
A flaw was found in WebKitGTK. This vulnerability allows remote, user-assisted information disclosure that can reveal an
A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from a
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val
Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on
NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. The
NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which
NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o
NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User
Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 't
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior
The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi
MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The M
Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p
Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via
Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer pr
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbi
Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker
Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru
Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i
EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/im
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker
Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parame
Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()',
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded
Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the
The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type
The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated u
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of
In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of p
In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation
In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr
In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started