Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verific
The Blackmagic ATEM Mini Pro 2.7 exposes an undocumented Telnet service on TCP port 9993, which accepts unauthenticated
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpo
Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can
In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr
A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. The affected element is a
A weakness has been identified in Campcodes Farm Management System 1.0. Impacted is an unknown function of the file /upl
CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The
The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malici
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users
Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When access
IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute co
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials. A r
A vulnerability has been found in Tenda AC23 up to 16.03.07.52. Affected by this vulnerability is the function sscanf of
A flaw has been found in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /administr
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function i
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. This affects an unkno
A weakness has been identified in itsourcecode Online Discussion Forum 1.0. The impacted element is an unknown function
The txtai framework allows the loading of compressed tar files as embedding indices. While the validate function is inte
A security flaw has been discovered in code-projects Hostel Management System 1.0. The affected element is an unknown fu
A vulnerability was identified in code-projects Hostel Management System 1.0. Impacted is an unknown function of the fil
A vulnerability was determined in code-projects Hostel Management System 1.0. This issue affects some unknown processing
A vulnerability was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the
A vulnerability has been found in code-projects Online Bidding System 1.0. This affects an unknown part of the file /adm
A vulnerability was detected in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown funct
A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /gofor
A weakness has been identified in code-projects Online Bidding System 1.0. This impacts an unknown function of the file
A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc
A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. The impacted element is an unknown
A vulnerability was determined in SourceCodester Online Hotel Reservation System 1.0. The affected element is an unknown
A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This vulnerability affects unknown code of th
A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown part of the fi
A security vulnerability has been detected in Campcodes Online Learning Management System 1.0. Affected by this issue is
A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected by this vulnerability is an
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Affected is an unknown function
A vulnerability was identified in Campcodes Online Learning Management System 1.0. This impacts an unknown function of t
A vulnerability was found in D-Link DCS-935L up to 1.13.01. The impacted element is the function sub_402280 of the file
A security flaw has been discovered in B-Link BL-AC2100 up to 1.0.3. Affected by this issue is the function delshrpath o
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Si
A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file
A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /g
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via craft
An issue was discovered in PPress 0.0.9 allowing attackers to gain escilated privlidges via crafted session cookie.
Hardcoded credentials in default configuration of PPress 0.0.9.
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 25.2.169 and Application prior to 25.2.1518 (VA and
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker co
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) provision the app
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1049 and Application versions prior t
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started