Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ult
The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
A vulnerability was found in Fujian Kelixun 1.0. It has been classified as critical. This affects an unknown part of the
A vulnerability was found in TOZED ZLT W51 up to 1.4.2 and classified as critical. Affected by this issue is some unknow
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory cor
OpenFGA is an authorization/permission engine. OpenFGA versions 1.8.0 through 1.8.12 (corresponding to Helm chart openfg
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized a
Schule is open-source school management system software. The generateOTP() function generates a 4-digit numeric One-Time
An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privile
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the SETTINGSVATIGATOR.EXE c
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the STOCKORDERENTRY.EXE com
An issue in Ocuco Innovation v.2.10.24.51 allows a local attacker to escalate privileges via the JOBENTRY.EXE
An issue in Ocuco Innovation APPMANAGER.EXE v.2.10.24.51 allows a local attacker to escalate privileges via the applicat
An issue in Ocuco Innovation Tracking.exe v.2.10.24.51 allows a local attacker to escalate privileges via the modificati
SSRF Server Side Request Forgery vulnerabilities exist in ASPECT if administrator credentials become compromisedThis iss
2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator
One way hash with predictable salt vulnerabilities in ASPECT may expose sensitive information to a potential attackerThi
Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informat
Fiber is an Express-inspired web framework written in Go. Starting in version 2.52.6 and prior to version 2.52.7, `fiber
Remote Code Execution vulnerabilities are present in ASPECT if session administrator credentials become compromised This
Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. Th
In Infoblox NETMRI before 7.6.1, authenticated users can perform SQL injection attacks.
Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials be
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become comp
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session adm
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Aste
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve
Insecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer clou
An insecure file system permissions vulnerability in MSP360 Backup 8.0 allows a low privileged user to execute commands
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau
IBM Aspera Faspex 5.0.0 through 5.0.12 could allow an authenticated user to obtain sensitive information or perform unau
Absolute File Traversal vulnerabilities in ASPECT allows access and modification of unintended resources. This issue aff
A vulnerability classified as critical was found in Campcodes Cybercafe Management System 1.0. Affected by this vulnerab
Insecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the cust
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function webExcptypemanFil
A flaw has been found in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected by this vulnerability is an unknown f
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated atta
Insecure permissions in measure-cold-start v1.4.1 allows attackers to escalate privileges and compromise the customer cl
An issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 befor
A vulnerability was detected in PHPGurukul/Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been classified as critical. This affects an u
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started