The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confir
The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registrat
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an u
@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization in
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/pro
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, co
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42,
A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed clu
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random b
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setu
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the
ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. Th
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input se
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output pa
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can resu
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to imp
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creat
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-hand
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands wit
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when c
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when install
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted
Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_EN
CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privile
CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post cr
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execu
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access a
Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a cli
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth f
SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that
SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing a
SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthen
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymou
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and ge
siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthen
SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly access
Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerab
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerab
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoo
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoo
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that u
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to imprope
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started