XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10
XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.
XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros tha
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Gro
XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or pr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal etracker al
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple Klar
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Con
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrari
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory travers
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to se
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized l
Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a cu
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
An improper neutralization of wildcards vulnerability in the log collection feature of Palo Alto Networks GlobalProtect™
A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform
Dell iDRAC Tools, version(s) prior to 11.3.0.0, contain(s) an Improper Access Control vulnerability. A low privileged at
Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer act
User names used to access the web management interface are limited to the device identifier, which is a numerical ident
A username and password are required to authenticate to the central SinoTrack device management interface. The username
AVEVA PI Data Archive products are vulnerable to an uncaught exception that, if exploited, could allow an authenticated
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is
There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with networ
Improper input validation was discovered in UsbCoreDxe in Insyde InsydeH2O kernel 5.4 before 05.47.01, 5.5 before 05.55.
Buffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the o
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP
The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an a
A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of conf
All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor an
Files in the source code contain login credentials for the admin user and the property configuration password, allowing
Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive infor
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain cond
An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to ac
The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to arbitr
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and Updat
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 could allow an a
An unrestricted file upload vulnerability exists in the Product Image section of the VirtueMart backend. Authenticated a
A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasse
Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of th
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. Th
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started