A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve
Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network
Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera
Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue a
The TLS4B ATG system is vulnerable to improper handling of Unix time values that exceed the 2038 epoch rollover. When th
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi
Vault and Vault Enterprise (“Vault”) are vulnerable to an unauthenticated denial of service when processing JSON payload
Captive Portal can expose sensitive information
Captive Portal can allow authentication bypass
Diagnostics command injection vulnerability
Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 stores authentication tokens in a file locat
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause uninitiali
NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful e
Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co
OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th
OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v
Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.
A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack
A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker
Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft
Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability
pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability
Admidio is an open-source user management solution. Prior to version 4.3.17, an authenticated SQL injection vulnerabilit
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe
Multiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function.
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set
Multiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial o
Multiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to ca
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan fun
A NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to caus
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenti
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaust
Tenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient functi
A NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a De
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBa
TOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiF
In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible f
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject for
my little forum is a PHP and MySQL based internet forum that displays the messages in classical threaded view. Prior to
MeterSphere is an open source continuous testing platform. Prior to version 2.10.25-lts, a logic flaw allows retrieval o
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started