An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-cre
ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed du
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain
Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t
Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e
Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code exe
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint th
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthe
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to
nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the na
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the
is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context o
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker coul
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute cod
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to byp
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execu
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges ov
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started