A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects un
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the fi
The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error
Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler o
Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a cal
With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy
The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up
MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a
This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) ap
In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session K
The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra
Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by def
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi
Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue
Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Obje
In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operation
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec
The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p
The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi
The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG
The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida
The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi
The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc
Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitr
The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u
Kafka dissector crash in Wireshark 4.6.0 and 4.4.0 to 4.4.10 allows denial of service
OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z
vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor
A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile
Microsoft Defender Portal Spoofing Vulnerability
Azure Monitor Elevation of Privilege Vulnerability
IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2
Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe
The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary fil
Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex
Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, with
SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to
SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recov
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. Th
Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly.
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to ca
A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started