INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows rem
INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote
INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote
INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote
INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote
Luxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remot
Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive inform
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive inf
In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 cha
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects
In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. Th
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side
A vulnerability was found in code-projects Church Donation System 1.0. It has been rated as critical. Affected by this i
Missing Authorization vulnerability in Drupal File Download allows Forceful Browsing.This issue affects File Download: f
In H3C GR2200 MiniGR1A0V100R016, the USERLIMIT_GLOBAL option is set to 0 in the /etc/bftpd.conf. This can cause DoS atta
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggres
A vulnerability was found in code-projects Church Donation System 1.0. It has been declared as critical. Affected by thi
A vulnerability was found in code-projects Church Donation System 1.0. It has been classified as critical. Affected is a
In TRENDnet TPL-430AP FW1.0, the USERLIMIT_GLOBAL option is set to 0 in the bftpd-related configuration file. This can c
In Netgear R7000 V1.3.1.64_10.1.36 and EAX80 V1.0.1.70_1.0.2, the USERLIMIT_GLOBAL option is set to 0 in the bftpd.conf
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the str
A vulnerability was found in code-projects Church Donation System 1.0 and classified as critical. This issue affects som
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjac
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants Within an Executable.
Authorization Bypass Through User-Controlled Key vulnerability in PAVO Inc. PAVO Pay allows Exploitation of Trusted Iden
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead
Authorization Bypass Through User-Controlled Key vulnerability in Turpak Automatic Station Monitoring System allows Priv
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-EC
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App St
File access paths in configuration files uploaded by users with administrator access are not validated. This issue affe
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affe
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to
Authorization Bypass Through User-Controlled Key vulnerability in Turtek Software Eyotek allows Exploitation of Trusted
The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An at
WinMatrix3 Web package developed by Simopro Technology has an Arbitrary File Upload vulnerability, allowing remote attac
A vulnerability was found in Chanjet CRM 1.0 and classified as critical. Affected by this issue is some unknown function
A vulnerability has been found in Tenda AC6 15.03.06.50 and classified as critical. Affected by this vulnerability is th
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. Affected is the funct
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4.1.5cu.748_B20211015. This issue affec
A vulnerability classified as critical was found in D-Link DI-8100 1.0. This vulnerability affects the function sprintf
A vulnerability classified as critical has been found in D-Link DIR-513 1.10. This affects the function sprintf of the f
A vulnerability was found in D-Link DIR-513 1.0. It has been rated as critical. Affected by this issue is the function s
A vulnerability was found in D-Link DI-8100 1.0. It has been declared as critical. Affected by this vulnerability is the
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started