The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKi
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a v
A vulnerability classified as critical was found in CesiumLab Web up to 4.0. This vulnerability affects unknown code of
Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kern
The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i
A vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could a
A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts se
The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or insta
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function l
The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, whic
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker
IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certifi
The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CS
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by
MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP reques
skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
The installer for SAN Host Utilities for Windows versions prior to 8.0 is susceptible to a vulnerability which when succ
In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer whil
Tyler Technologies ERP Pro 9 SaaS allows an authenticated user to escape the application and execute limited operating s
GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installati
A cross-site scripting (XSS) vulnerability in the PdfViewer component of Agenzia Impresa Eccobook 2.81.1 allows attacker
Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter i
Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the user
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username paramet
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress par
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStuden
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createSessio
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassA
LinkJoin through 882f196 mishandles token ownership in password reset.
LinkJoin through 882f196 mishandles lacks type checking in password reset.
Authentication Bypass Using an Alternate Path or Channel vulnerability in Saad Iqbal Post SMTP post-smtp allows Authenti
Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method
On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from t
Use after free in Cast in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit heap cor
Use after free in Extensions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to potentially exploit he
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. In versions 0.8.0 through 0.9.21 and 1.
EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Succes
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions an
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.
A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerabili
A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A
An unrestricted file upload vulnerability in Vedo Suite version 2024.17 allows remote authenticated attackers to write t
Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 202
Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a A
Cross-site scripting (XSS) vulnerability in Zone Bitaqati thru 3.4.0.
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HT
poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started