A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is an
A vulnerability classified as critical was found in TOTOLINK T10 4.1.8cu.5207. Affected by this vulnerability is the fun
A vulnerability classified as critical has been found in TOTOLINK T10 4.1.8cu.5207. Affected is the function setWiFiSche
Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts functi
A vulnerability has been found in Chanjet CRM 1.0 and classified as critical. Affected by this vulnerability is an unkno
Privilege Escalation in MiniOS in Google ChromeOS (16063.45.2 and potentially others) on enrolled devices allows a local
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This issue
A vulnerability classified as critical was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This vulnerability affects
A vulnerability classified as critical has been found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. This affects an unknow
A NULL pointer dereference vulnerability was found in libxml2 when processing XPath XML expressions. This flaw allows an
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or Pos
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer fo
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat:
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons Fil
SessionClicks in Liferay Portal 7.0.0 through 7.4.3.21, and Liferay DXP 7.4 GA through update 9, 7.3 GA through update 2
A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects so
Liferay Portal 7.4.0 through 7.4.3.97, and Liferay DXP 2023.Q3.1 through 2023.Q3.2, 7.4 GA through update 92, 7.3 GA thr
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute c
A vulnerability has been found in code-projects Restaurant Order System 1.0 and classified as critical. This vulnerabili
A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the fir
A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been rated as critical. This issue affe
A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been declared as critical. This vulnera
A vulnerability was found in Das Parking Management System 停车场管理系统 6.2.0. It has been classified as critical. This affec
A vulnerability was found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this issue is the function
A vulnerability has been found in D-Link DIR-619L 2.06B01 and classified as critical. Affected by this vulnerability is
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retr
A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. Affected is the function fromadvse
A vulnerability, which was classified as critical, has been found in Tenda FH1205 2.0.0.7. This issue affects the functi
A stored Cross-site Scripting (XSS) vulnerability affecting Opportunity Management in Project Portfolio Manager from Rel
A vulnerability classified as critical was found in Tenda FH1205 2.0.0.7(775). This vulnerability affects the function f
A vulnerability classified as critical has been found in Tenda FH1201 1.2.0.14(408). This affects an unknown part of the
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affecte
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnera
A vulnerability, which was classified as critical, was found in codesiddhant Jasmin Ransomware 1.0.1. Affected is an unk
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a
A vulnerability was found in H3C GR-3000AX V100R007L50. It has been classified as critical. Affected is the function Upd
A vulnerability was found in H3C GR-5400AX V100R009L50 and classified as critical. This issue affects the function Updat
IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root d
The Zagg - Electronics & Accessories WooCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusi
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordP
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va
IBM Backup, Recovery and Media Services for i 7.4 and 7.5 could allow a user with the capability to compile or restore a
An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell
A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 p
An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior
A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior
An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.1
XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifi
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes applic
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started