An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vuln
In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid
The B1.lt plugin for WordPress is vulnerable to SQL Injection due to a missing capability check on the b1_run_query AJAX
The aapanel WP Toolkit plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks wi
The School Management System for Wordpress plugin for WordPress is vulnerable to Local File Inclusion in all versions up
A vulnerability classified as critical was found in code-projects Online Appointment Booking System 1.0. Affected by thi
A vulnerability classified as critical has been found in code-projects Online Appointment Booking System 1.0. Affected i
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 up to 4.1.5cu.748_B20211015. Affected b
A vulnerability in the ascgshell, of Brocade ASCG before 3.3.0 stores any command executed in the Command Line Interfa
A vulnerability classified as critical was found in PHPGurukul Land Record System 1.0. Affected by this vulnerability is
A vulnerability was found in code-projects Online Appointment Booking System 1.0. It has been classified as critical. Th
A vulnerability was found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affected by
A vulnerability has been found in code-projects Online Appointment Booking System 1.0 and classified as critical. Affect
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and o
A cross-site scripting (XSS) vulnerability was reported in the Lenovo Browser that could allow an attacker to obtain sen
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local at
A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS dist
NVIDIA Jetson Linux contains a vulnerability in UEFI Management mode, where an unprivileged local attacker may cause exp
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could
A DLL hijacking vulnerability was reported in the Motorola Software Fix (Rescue and Smart Assistant) installer that coul
An incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authe
A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff
A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, aff
A code injection vulnerability has been identified in the Robot Operating System (ROS) 'roslaunch' command-line tool, af
A code execution vulnerability has been discovered in the Robot Operating System (ROS) 'rosparam' tool, affecting ROS di
A vulnerability, which was classified as critical, was found in code-projects Online Appointment Booking System 1.0. Aff
A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a loc
7-Zip is a file archiver with a high compression ratio. 7-Zip supports extracting from Compound Documents. Prior to vers
7-Zip is a file archiver with a high compression ratio. Zeroes written outside heap buffer in RAR5 handler may lead to m
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause es
SQL Injection vulnerability in cnhcit.com Haichang OA v.1.0.0 allows a remote attacker to obtain sensitive information v
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability that is present starting in version 1
Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via th
OA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection
When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream brid
The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote a
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started