Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may
Status verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability will
Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect
Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect
Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParse
A denial-of-service vulnerability exists in Sysax Multi-Server version 6.10 via its SSH daemon. A specially crafted SSH
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie para
Insecure Direct Object Reference (IDOR) vulnerability in PdfHandler component in Agenzia Impresa Eccobook v2.81.1 and be
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Refe
Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vul
An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute ar
A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote ser
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to re
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati
A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.
The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting
LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint
Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missin
js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype
The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large person
An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a mal
CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnera
Paramount Macrium Reflect through 2025-06-26 allows local attackers to execute arbitrary code with administrator privile
Paramount Macrium Reflect through 2025-06-26 allows attackers to execute arbitrary code with administrator privileges vi
Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An unauthenticated remote at
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded Cryptographic Key vulnerabi
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Si
A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP hea
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.
Dell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remo
Certain Draytek products are affected by Insecure Configuration. This affects AP903 v1.4.18 and AP912C v1.4.9 and AP918R
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arb
Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read o
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authen
Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 throu
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime system
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and wri
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remo
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started