Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics
Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrar
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the oper
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing ar
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hosti
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to under
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as t
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause
Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter th
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.i
GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fail
GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing atta
GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handl
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing
Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where use
Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplie
Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw comm
Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns,
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete op
SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an au
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)
: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priorit
@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can
@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart f
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulner
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started