A Use After Free vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Ju
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenti
An Incorrect Permission Assignment for Critical Resource vulnerability in line card script processing of Juniper Network
The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters i
The communication protocol used between the server process and the service control had a flaw that could lead to a local
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been declared as critical. This
A vulnerability was found in Tenda FH451 up to 1.0.0.9 and classified as critical. Affected by this issue is the functio
A vulnerability classified as critical was found in Tenda O3V2 1.0.0.12(3880). Affected by this vulnerability is the fun
A vulnerability classified as critical has been found in Tenda O3V2 1.0.0.12(3880). Affected is the function setAutoRebo
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been rated as critical. This issue affects the function f
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been declared as critical. This vulnerability affects the
A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServle
A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through Network
A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServl
Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to anothe
A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() fun
Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense agai
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fr
A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the functio
The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH
A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability i
A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function from
The Honeywell Experion PKS contains an Integer Underflow vulnerability in the component Control Data Access (CDA). A
The Honeywell Experion PKS and OneWireless WDM contains a Deployment of Wrong Handler vulnerability in the comp
The Honeywell Experion PKS and OneWireless WDM contains a Memory Buffer vulnerability in the component Control Data Acce
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes h
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests usi
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial set
The Honeywell Experion PKS contains an Uninitialized Variable in the common Epic Platform Analyzer (EPA) communications.
A vulnerability was found in code-projects LifeStyle Store 1.0. It has been declared as critical. Affected by this vulne
Headlamp is an extensible Kubernetes web UI. A command injection vulnerability was discovered in the codeSign.js script
Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to u
A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have all
Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalat
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc
Insecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain
An issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component.
A vulnerability was found in code-projects LifeStyle Store 1.0. It has been classified as critical. Affected is an unkno
A vulnerability was found in code-projects Mobile Shop 1.0 and classified as critical. This issue affects some unknown p
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Ser
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63
Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a maliciou
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type respons
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started