Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic
The administrator password setting of the D-Link DIR-820L 1.06B02 is has Improper Access Control and is vulnerable to Un
Cross site scripting vulnerability in Moodle GeniAI plugin (local_geniai) 2.3.6. An authenticated user with Teacher role
astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 co
QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass
The incomplete verification mechanism in the AutoBizLine com.mysecondline.app 1.2.91 allows attackers to log in as other
GeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
This High severity DoS (Denial of Service) vulnerability was introduced in version 2.0 of Confluence Data Center. Thi
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker
Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key u
All WorkExaminer Professional traffic between monitoring client, console and server is transmitted as plain text. This a
The WorkExaminer Professional server installation comes with an FTP server that is used to receive the client logs on TC
EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthentic
A missing authorization vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, USG FLEX series fi
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.40, US
A command injection vulnerability may be exploited after the admin's authentication on the web portal on Omada gateways.
An arbitrary OS command may be executed on the product by the user who can log in to the web management interface.
Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows at
SQL Injection vulnerability in opentext Flipper allows SQL Injection. The vulnerability could allow a low privilege us
Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac
Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0.
An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary cod
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In version 1.4.0
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip Time Pro
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Microchip Ti
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB C
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbi
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix warning in smc_rx_splice() when callin
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix folio is still mapped when deleted
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210
An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128
Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Att
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide cus
An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A s
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to by
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Den
Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limitin
ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged
A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality
A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing
A security vulnerability has been detected in LibreWolf up to 143.0.4-1 on Windows. This affects an unknown function of
Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could all
The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started