The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via
The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus
In Tenable Nessus versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrit
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a
Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a
@cyanheads/git-mcp-server is an MCP server designed to interact with Git repositories. Prior to version 2.1.5, there is
Misconfigured settings in IITB SSO v1.1.0 allow attackers to access sensitive application data.
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may cont
It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit
A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a
A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected
A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi
A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow
A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects
A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil
Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects
A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue
A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an un
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lz
Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with pr
A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability
A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown f
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue a
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Fro
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vuln
A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This af
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write v
A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec valu
A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to t
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerab
A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, a carefully crafted request cou
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4.1.5cu.748_B20211015. This affects the func
Frappe is a full-stack web application framework. Prior to versions 14.94.3 and 15.58.0, SQL injection could be achieved
string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allow
A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unkn
A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown pa
A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue aff
A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue
A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vul
A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started