Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink.
Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name.
Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramete
Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea a
Lack of file validation in do_update_vps in Avast Business Antivirus for Linux 4.5 on Linux allows local user to spoof o
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2.
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can uploa
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. Thi
A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code
LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the impro
The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio
An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 th
The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to a missing file type validati
Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'su
Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit h
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbit
ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged
A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been declared as critical. This vulnerability af
A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unk
A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is so
A vulnerability has been found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this vulner
An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of
A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 1.0. Affect
There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of
A vulnerability, which was classified as critical, has been found in Gowabby HFish 0.1. This issue affects the function
A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability
Django-Select2 is a Django integration for Select2. Prior to version 8.4.1, instances of HeavySelect2Mixin subclasses li
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been special
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been
A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.AN
Memory safety bugs present in Firefox 138 and Thunderbird 138. Some of these bugs showed evidence of memory corruption a
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability was fixed
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption a
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bu
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder
The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of
An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionalit
An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt
An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer
Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
A vulnerability classified as critical was found in PHPGurukul Company Visitor Management System 1.0. This vulnerability
A vulnerability classified as critical has been found in PHPGurukul Online Nurse Hiring System 1.0. This affects an unkn
A vulnerability was found in Campcodes Online Hospital Management System 1.0. It has been rated as critical. Affected by
A vulnerability was found in D-Link DI-8100 up to 20250523. It has been classified as critical. Affected is the function
A vulnerability was found in PHPGurukul Small CRM 3.0 and classified as critical. This issue affects some unknown proces
A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknow
A vulnerability, which was classified as critical, was found in Campcodes Advanced Online Voting System 1.0. This affect
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started