On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the B
When using domain users as BRAIN2 users, communication with Active Directory services is unencrypted. This can lead to t
The service Bizerba Communication Server (BCS) has an unquoted service path. Due to the way Windows searches the executa
Agno is a multi-agent framework, runtime and control plane. From 2.0.0 to before 2.2.2, under high concurrency, when ses
DLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerabi
Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow a non-root user to gain higher privileges/capabi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Deserialization of Untrusted Data vulnerability in Chouby Polylang polylang allows Object Injection.This issue affects P
When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi
The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached
Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict inform
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and includi
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user
LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api
Scrapy versions up to 2.13.2 are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompressio
SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted paylo
A vulnerability was identified in certain UniFi Talk devices where internal debugging functionality remained unintention
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodical
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run C
Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validatio
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management function
Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligenc
Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacke
Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The
Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizar
Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient valida
Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handli
Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account inform
Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the requir
Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, lo
Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/per
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulner
Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitati
Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The s
Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functional
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started