A vulnerability, which was classified as critical, has been found in itsourcecode Placement Management System 1.0. Affec
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser enc
A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, was found in PHPGurukul Company Visitor Management System 2.0. Affect
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this i
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by thi
Emlog is an open source website building system. In versions up to and including 2.5.9, SQL injection occurs because the
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
The Taskbuilder WordPress plugin before 3.0.9 does not sanitize and escape a parameter before using it in a SQL stateme
The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthent
The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which co
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before
The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL
The Connexion Logs WordPress plugin through 3.0.2 does not sanitize and escape a parameter before using it in a SQL stat
The AHAthat Plugin WordPress plugin through 1.6 does not sanitize and escape a parameter before using it in a SQL statem
The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL sta
The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting i
The Advanced Schedule Posts WordPress plugin through 2.1.8 does not sanitise and escape a parameter before outputting it
The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id paramete
The illi Link Party! WordPress plugin through 1.0 lacks proper access controls, allowing unauthenticated visitors to del
The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisa
The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisa
The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is a
A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects som
A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerabilit
Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This iss
Dell PowerScale InsightIQ, versions 5.0 through 5.2, contains an improper privilege management vulnerability. An unauthe
Dell PowerScale OneFS, versions 9.4.0.0 through 9.9.0.0, contains an uncontrolled resource consumption vulnerability. A
A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects a
A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected
A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerabi
A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknow
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects
A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnera
There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when
There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolE
There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the Symb
There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in N
There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the Symbol
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by t
A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected
In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the curren
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started