Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics)
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1
An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1
Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p
Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confi
Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition poten
Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, a
A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced
Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using
The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downl
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allo
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST
ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName.
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer
A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERI
The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit
Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker
NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servic
An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denia
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of th
The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it bac
The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputtin
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In
A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /
A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functiona
A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of
A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi.
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the
A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/res
A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functional
Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially result
A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resul
A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality
A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file
A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formP
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an un
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown functi
A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNt
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started