A vulnerability has been found in Jinher OA 1.0. This issue affects some unknown processing of the file GetTreeDate.aspx
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a cra
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7
Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a
An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote att
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrato
A vulnerability was determined in code-projects Simple Grading System 1.0. This affects an unknown function of the file
A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown func
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code
Hosts listed in TrustedOrigins implicitly allow requests from the corresponding HTTP origins, allowing network MitMs to
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root dur
Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical sys
A vulnerability was identified in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file
A vulnerability was determined in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown f
A vulnerability was found in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS c
The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attacker
A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown process
Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers t
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated u
A vulnerability was detected in itsourcecode Apartment Management System 1.0. This affects an unknown part of the file /
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. Affected by this issue is so
A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unk
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6. A malicious a
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7
CGI::Simple versions before 1.282 for Perl has a HTTP response splitting flaw This vulnerability is a confirmed HTTP res
A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of
A vulnerability was identified in itsourcecode Apartment Management System 1.0. This impacts an unknown function of the
A vulnerability was determined in itsourcecode Sports Management System 1.0. This affects an unknown function of the fil
A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown funct
A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /repo
A vulnerability was detected in itsourcecode Apartment Management System 1.0. This issue affects some unknown processing
A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit whic
Tenda AC10 v4.0 firmware v16.03.10.20 was discovered to contain a stack overflow via the function get_parentControl_list
Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-p
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.15.2, 21.10.2, and 22.5.2
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload an
A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system.
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This
Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showc
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started