A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extracta
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an un
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unk
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.1
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is a
A vulnerability was determined in Campcodes Online Loan Management System 1.0. This issue affects some unknown processin
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the OAuth client creation and update endp
Fides is an open-source privacy engineering platform. Prior to version 2.69.1, the Fides Webserver API's built-in IP-bas
A vulnerability was found in Campcodes Online Loan Management System 1.0. This vulnerability affects unknown code of the
Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Ma
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke
A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func
The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the
A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac
A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries
FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Colum
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacke
JSON::SIMD before version 1.07 and earlier for Perl has an integer buffer overflow causing a segfault when parsing craft
JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabl
The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended dr
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. P
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream whi
A vulnerability (CVE-2025-21172) exists in msdia140.dll due to integer overflow and heap-based overflow. Per CWE-122:
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectman
A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.proje
A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.dep
Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacke
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufactu
A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates
The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoi
A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file
A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the fil
A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /a
A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function
A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_de
In the Linux kernel, the following vulnerability has been resolved: mm: swap: fix potential buffer overflow in setup_cl
A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/a
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part o
Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. All versions o
xgrammar is an open-source library for efficient, flexible, and portable structured generation. A grammar optimizer intr
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started