A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability
A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Re
A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in Collaborative Industry Innovator from Release 3
A stored Cross-site Scripting (XSS) vulnerability affecting Change Governance in Product Manager from Release 3DEXPERIEN
A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in Product Manager from Release 3DEXPERIENCE R2
A stored Cross-site Scripting (XSS) vulnerability affecting Results Analytics in Multidisciplinary Optimization Engineer
A stored Cross-site Scripting (XSS) vulnerability affecting Model Definition in Product Manager from Release 3DEXPERIENC
A stored Cross-site Scripting (XSS) vulnerability affecting Risk Management in Project Portfolio Manager from Release 3D
A stored Cross-site Scripting (XSS) vulnerability affecting City Discover in City Referential Manager on Release 3DEXPER
A stored Cross-site Scripting (XSS) vulnerability affecting City Referential in City Referential Manager on Release 3DE
A stored Cross-site Scripting (XSS) vulnerability affecting Compare in Collaborative Industry Innovator from Release 3DE
Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter wooc
Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrativ
A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an
The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass
Due to excessive privileges granted to the web user running the airpointer web platform, a malicious actor that gains co
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vuln
GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with acc
Client-side enforcement of server-side security issue exists in wivia 5 all versions. If exploited, an unauthenticated a
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS comman
Valtimo is a platform for Business Process Automation. In versions starting from 11.0.0.RELEASE to 11.3.3.RELEASE and 12
Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user rec
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile
Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create
A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some u
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o
Santesoft Sante DICOM Viewer Pro contains a memory corruption vulnerability. A local attacker could exploit this issue t
A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 1
MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a ch
An issue in OpenKnowledgeMaps Headstart v7 allows a remote attacker to escalate privileges via the url parameter of the
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly chec
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, there is no check to ensure that
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deser
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Des
tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c.
In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix unsafe attribute parsing in output
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix uninitialized memcache pointer in u
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started