Missing Authorization vulnerability in kamleshyadav WP Lead Capturing Pages leadcapture allows Exploiting Incorrectly Co
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alvind Billplz Add
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rico Macchi WP Lin
Missing Authorization vulnerability in ThemeAtelier IDonatePro idonate-pro allows Exploiting Incorrectly Configured Acce
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt FoodMenu al
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomIt WooCommerce
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redqteam Alike - W
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
A vulnerability has been found in PHPGurukul Hospital Management System 4.0. This vulnerability affects unknown code of
A vulnerability was identified in PHPGurukul Hospital Management System 4.0. This affects an unknown part of the file /a
A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some
A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an
Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows atta
Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi
A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) att
A vulnerability has been found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of t
A vulnerability was identified in Campcodes Online Recruitment Management System 1.0. This issue affects some unknown pr
A vulnerability was identified in D-Link DIR-825 2.10. Affected by this vulnerability is the function get_ping_app_stat
A vulnerability was determined in projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi
A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of
A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown co
A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of
A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/Wifi
A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown func
A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown fun
A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of
pypdf is a free and open-source pure-python PDF library. Prior to version 6.0.0, an attacker can craft a PDF which leads
A vulnerability was found in SourceCodester COVID 19 Testing Management System 1.0. Affected by this vulnerability is an
KuWFi 5G01-X55 FL2020_V0.0.12 devices expose an unauthenticated API endpoint (ajax_get.cgi), allowing remote attackers t
A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file
A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing
A vulnerability was determined in code-projects Job Diary 1.0. This vulnerability affects unknown code of the file /edit
A vulnerability was found in code-projects Job Diary 1.0. This affects an unknown part of the file /admin-inbox.php. The
A vulnerability has been found in code-projects Job Diary 1.0. Affected by this issue is some unknown functionality of t
Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ director
Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM z
An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditio
An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgite
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgite
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgite
NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a co
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could c
NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started