A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affec
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. This af
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by
A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerabili
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown
A vulnerability was found in code-projects Exam Form Submission 1.0. It has been rated as critical. This issue affects s
A vulnerability was found in code-projects Online Ordering System 1.0. It has been declared as critical. This vulnerabil
A vulnerability was found in code-projects Online Ordering System 1.0. It has been classified as critical. This affects
A vulnerability was found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this issue
A vulnerability has been found in code-projects Online Ordering System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, was found in code-projects Online Ordering System 1.0. Affected is an
A vulnerability has been found in Engeman Web up to 12.0.0.2. The affected element is an unknown function of the file /L
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
A vulnerability was found in 1000 Projects ABC Courier Management System 1.0. It has been classified as critical. Affect
A vulnerability was found in D-Link DIR-513 up to 1.10 and classified as critical. This issue affects the function formS
The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.0 via t
The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in t
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1.0.0.1. This affects an unkno
A vulnerability, which was classified as critical, has been found in Tenda CH22 1.0.0.1. Affected by this issue is the f
The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affec
A vulnerability classified as critical has been found in Tenda AC10 16.03.10.13. Affected is an unknown function of the
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and below of haxcm
FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to
A vulnerability has been found in 1000 Projects ABC Courier Management System 1.0 and classified as critical. Affected b
A vulnerability classified as critical was found in TOTOLINK T6 4.1.5cu.748_B20211015. This vulnerability affects the fu
A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function formSetWanPPTPca
A vulnerability was found in D-Link DIR-513 1.10. It has been rated as critical. Affected by this issue is the function
Cross Site Scripting vulnerability in grav v.1.7.48, v.1.7.47 and v.1.7.46 allows an attacker to execute arbitrary code
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector mod
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source module
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Serve
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initi
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc a
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: befo
goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.
Unitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded
In the Linux kernel, the following vulnerability has been resolved: perf: Revert to requiring CAP_SYS_ADMIN for uprobes
In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_conn_close(). syz
In the Linux kernel, the following vulnerability has been resolved: tcp: Correct signedness in skb remaining space calc
In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment
In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix potential null-ptr-deref in to_atmar
In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix infinite recursive call of clip_push
In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Fix potential memory corruption in
In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Reject SEV{-ES} intra host migration if v
In the Linux kernel, the following vulnerability has been resolved: io_uring/msg_ring: ensure io_kiocb freeing is defer
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started