In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of serv
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of serv
A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected by this vulnerabili
A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of
A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /media
The installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurel
A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function e
A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /t
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fe
A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is
Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.1
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not i
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains a
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQ
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-sid
CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0.
Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin
WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in
app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela
Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi
Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec
DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may
Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may
UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af
An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo
An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025
The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo
Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths
The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida
The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe
Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started