A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a mali
In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privilege
GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certa
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to
In the Linux kernel, the following vulnerability has been resolved: iommu/s390: Make attach succeed when the device was
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Curr
In the Linux kernel, the following vulnerability has been resolved: igc: don't fail igc_probe() on LED setup error Whe
In the Linux kernel, the following vulnerability has been resolved: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconne
The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr
The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable
Memory corruption while invoking remote procedure IOCTL calls.
Memory corruption while allocating buffers in DSP service.
Memory corruption while processing user buffers.
Memory corruption while processing an escape call.
Memory corruption while processing control commands in the virtual memory management interface.
Transient DOS may occur when multi-profile concurrency arises with QHS enabled.
memory corruption while processing an image encoding completion event.
Memory corruption while processing IOCTL call to get the mapping.
Memory corruption while processing escape commands from userspace.
Memory corruption while performing SCM call with malformed inputs.
Memory corruption while performing SCM call.
Memory corruption while processing a malformed license file during reboot.
Memory corruption during PlayReady APP usecase while processing TA commands.
Memory corruption while processing camera platform driver IOCTL calls.
A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/
A vulnerability was identified in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/saveAutoQo
A vulnerability was determined in Tenda AC7 15.03.06.44. The impacted element is an unknown function of the file /goform
A vulnerability was found in Tenda AC7 15.03.06.44. The affected element is an unknown function of the file /goform/Wifi
A vulnerability has been found in Tenda AC7 15.03.06.44. Impacted is an unknown function of the file /goform/SetUpnpCfg.
A flaw has been found in Tenda AC7 15.03.06.44. This issue affects some unknown processing of the file /goform/SetDDNSCf
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in
A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown fu
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unkno
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of th
ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php pag
A vulnerability was determined in PHPGurukul Beauty Parlour Management System 1.1. This issue affects some unknown proce
An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and bef
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject
A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Execu
Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.
Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system
A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown funct
A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the
A security flaw has been discovered in SourceCodester Wedding Reservation Management System 1.0. This vulnerability affe
A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the fi
A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u
A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function
A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the f
A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function o
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started