An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configura
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting
A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges
A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due t
An unauthenticated remote attacker can use MQTT messages to trigger out-of-bounds writes in charging stations complying
The Widget for Google Reviews plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected
A vulnerability has been found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affe
A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. This affects an unknown p
A vulnerability was found in code-projects Online Note Sharing 1.0. It has been classified as critical. Affected is an u
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (
The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a
A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extract
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database ta
A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr
Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker
A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affe
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which l
A vulnerability, which was classified as critical, has been found in Campcodes Online Recruitment Management System 1.0.
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an
A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The firmware file, rootfs.tar.gz,
Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP p
Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19,
An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length che
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this is
Marvell QConvergeConsole getDriverTmpPath Directory Traversal Information Disclosure Vulnerability. This vulnerability a
Marvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows r
Marvell QConvergeConsole compressFirmwareDumpFiles Directory Traversal Information Disclosure Vulnerability. This vulner
Marvell QConvergeConsole compressDriverFiles Directory Traversal Information Disclosure Vulnerability. This vulnerabilit
Marvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write Vulnerability. This vulnerability
Marvell QConvergeConsole restoreESwitchConfig Directory Traversal Information Disclosure Vulnerability. This vulnerabili
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability
Marvell QConvergeConsole getFileUploadBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability
Marvell QConvergeConsole getAppFileBytes Directory Traversal Information Disclosure Vulnerability. This vulnerability al
Marvell QConvergeConsole getFileUploadSize Directory Traversal Information Disclosure Vulnerability. This vulnerability
MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete dat
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization d
GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust th
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this
A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started