In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Cause
An authenticated arbitrary file upload vulnerability in the component /msg/sendfiles of DooTask v1.0.51 allows attackers
Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using JSONLayout, not all payload bytes a
User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutr
SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users
D-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-w
OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
An SQL injection vulnerability in Yoosee application v6.32.4 allows authenticated users to inject arbitrary SQL queries
Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does no
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions prior to 3.25.5, Roo-Code fa
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and
Incorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firm
A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with
Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 a
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parame
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName para
Tenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.
D-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.
Insecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via
An issue was discovered in Shopizer 3.2.7. The server's CORS implementation reflects the client-supplied Origin header v
An issue was discovered in the changePassword method in file /usr/share/php/openmediavault/system/user.inc in OpenMediaV
In the Linux kernel, the following vulnerability has been resolved: xfrm: state: initialize state_ptrs earlier in xfrm_
In the Linux kernel, the following vulnerability has been resolved: arm64/entry: Mask DAIF in cpu_switch_to(), call_on_
In the Linux kernel, the following vulnerability has been resolved: iio: fix potential out-of-bound write The buffer i
In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix use-after-free in AARP proxy pr
In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: mt8365-dai-i2s: pass correct size t
In the Linux kernel, the following vulnerability has been resolved: platform/x86: alienware-wmi-wmax: Fix `dmi_system_i
In the Linux kernel, the following vulnerability has been resolved: gfs2: No more self recovery When a node withdraws
In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: Do not complete commands twice if n
In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: mcc: prevent shift wrapping in rtw89_c
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_st
In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.p
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Add missing lock in cfg80211_check_
In the Linux kernel, the following vulnerability has been resolved: bpf: Disable migration in nf_hook_run_bpf(). syzbo
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nfacct: don't assume acct name is nul
In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using D
In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_
In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a
In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: fix list_del corruption I
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
IBM QRadar SIEM 7.5 through 7.5.0 UP13 could allow an authenticated user to escalate their privileges via a misconfigure
In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It
In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and pac
In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS UL
In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us
In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started