Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If thi
NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM
The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information whe
SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability
If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the clien
In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field i
O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition small-package-q
Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News instant-breaking-news allows Stored
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.
An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-
NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The sear
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu
SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4
A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form
GLPI, which stands for Gestionnaire Libre de Parc Informatique, is a Free Asset and IT Management Software package, that
A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include
A vulnerability was found in Linksys E1700 1.0.0.4.003. This affects the function QoSSetup of the file /goform/QoSSetup.
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged a
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resource vulner
A vulnerability has been found in Linksys E1700 1.0.0.4.003. Affected by this issue is the function setSysAdm of the fil
A flaw has been found in Linksys E1700 1.0.0.4.003. Affected by this vulnerability is the function setWan of the file /g
A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code
Multiple i-フィルター products contain an issue with incorrect default permissions. If this vulnerability is exploited, a loc
Incorrect privilege assignment vulnerability exists in ScanSnap Manager installers versions prior to V6.5L61. If this vu
A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an u
A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown pro
A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown functio
A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the f
A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file
A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionali
A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknow
A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown functi
A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the f
Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Midd
Agiloft Release 28 contains several accounts with default credentials that could allow local privilege escalation. The p
In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could
In process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. Th
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc
In rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This
In bnepu_check_send_packet of bnep_utils.cc, there is a possible way to achieve code execution due to a use after free.
In multiple locations, there is a possible way to execute arbitrary code due to a use after free. This could lead to loc
In avct_lcb_msg_ind of avct_lcb_act.cc, there is a possible way to execute arbitrary code due to a use after free. This
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started