A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processi
A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the fi
A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /
A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘s
A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the
A vulnerability has been found in itsourcecode Inventory Management System 1.0. The affected element is an unknown funct
A weakness has been identified in code-projects Simple Cafe Ordering System 1.0. This vulnerability affects unknown code
A vulnerability was identified in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown
A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the fil
A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the
A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena
The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f
The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow a
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote u
A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient em
Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination wi
A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers
An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Informati
npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use
A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknow
A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerabili
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. Wh
A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file a
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the
Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4
The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possib
IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo
The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA
Use after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a use
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potential
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the cl
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a
A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\
A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra
A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Ac
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitra
The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauth
A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a
A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a
A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element i
Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started