Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset
The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne
A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst
A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh
Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca
A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave
A vulnerability in the SSH restricted shell interface of the network management services allows improper access control
Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C ext
eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction
An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflow
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO
An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7
A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F
GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The mani
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty s
A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MS
Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacke
In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such
Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt co
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method
A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a
Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules.
A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th
A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem
The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl
The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to,
The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions
The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up
The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc
The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1
The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet
The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web
Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. Th
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(A
A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function o
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started