Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administra
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.27 a
Vulnerability in Oracle Java SE (component: Install). The supported version that is affected is Oracle Java SE: 8u451.
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payro
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t
Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.2
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Error
Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati
VMware ESXi, Workstation, Fusion, and VMware Tools contains an information disclosure vulnerability due to the usage of
Use after free in WebRTC in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap
Integer overflow in V8 in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially exploit heap co
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote at
In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was pos
ZITADEL is an open source identity management system. Starting in version 2.53.0 and prior to versions 4.0.0-rc.2, 3.3.2
SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in
Directory traversal vulnerability in beiyuouo arxiv-daily thru 2025-05-06 (commit fad168770b0e68aef3e5acfa16bb2e7a7765d6
NanoMQ 0.17.5 was discovered to contain a segmentation fault via the component /nanomq/pub_handler.c. This vulnerability
Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desk
Use of Uninitialized Variable vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release S
Use After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Deskt
Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR
Use After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWOR
Out-Of-Bounds Read vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS D
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the numbe
The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc
A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior
Nix is a package manager for Linux and other Unix systems. Builds with Nix 2.30.0 on macOS were executed with elevated p
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python par
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.
A segmentation fault in NanoMQ v0.21.10 allows attackers to cause a Denial of Service (DoS) via crafted messages.
A vulnerability was found in code-projects Mobile Shop 1.0. It has been declared as critical. This vulnerability affects
A vulnerability was found in code-projects Wedding Reservation 1.0. It has been classified as critical. This affects an
A vulnerability was found in code-projects Electricity Billing System 1.0 and classified as critical. Affected by this i
A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vu
A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an u
A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue
A vulnerability classified as critical has been found in code-projects AVL Rooms 1.0. This affects an unknown part of th
A vulnerability was found in code-projects AVL Rooms 1.0. It has been rated as critical. Affected by this issue is some
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as critical. Affected by th
A vulnerability was found in D-Link DI-8100 16.07.26A1. It has been classified as critical. Affected is an unknown funct
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started