A vulnerability was found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this issue is some unknown
A vulnerability has been found in FreeFloat FTP Server 1.0 and classified as critical. Affected by this vulnerability is
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve
Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. Starting in ve
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Fram
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara
Use of Password Hash With Insufficient Computational Effort vulnerability in Tridium Niagara Framework on Windows, Linux
Uncontrolled Search Path Element vulnerability in Forcepoint FIE Endpoint allows Privilege Escalation, Code Injection, H
A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. Affected is an unknown functio
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. This issue affects some u
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon ev
Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where imp
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redire
GStreamer H265 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows
Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attac
eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw
eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability
eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all
Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attac
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabil
GStreamer Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local atta
The Versa Concerto SD-WAN orchestration platform is vulnerable to an privileges escalation and container escape vulnerab
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. Affected by this issue
A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. Affected by this vu
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions
The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy
A vulnerability, which was classified as critical, has been found in FreeFloat FTP Server 1.0. Affected by this issue is
A vulnerability classified as critical was found in FreeFloat FTP Server 1.0. Affected by this vulnerability is an unkno
A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary P
An issue in OrangeHRM v.5.7 allows an attacker to escalate privileges via UserService.php and the checkForOldHash functi
A vulnerability classified as critical has been found in FreeFloat FTP Server 1.0. Affected is an unknown function of th
A vulnerability was found in FreeFloat FTP Server 1.0. It has been rated as critical. This issue affects some unknown pr
A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. This vulnerability affects unkn
A vulnerability in SeedDMS 6.0.32 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting t
XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a doc
jq is a command-line JSON processor. In versions up to and including 1.7.1, a heap-buffer-overflow is present in functio
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd,
A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown fu
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Events Log Track allows Excessive Allocatio
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthen
A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer
The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
The sr_feuser_register extension through 12.4.8 for TYPO3 allows Insecure Direct Object Reference.
The ns_backup extension through 13.0.0 for TYPO3 has a Predictable Resource Location.
An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted exe
An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started