Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into
A vulnerability was found in Netgear JWNR2000v2 1.0.0.11. It has been classified as critical. Affected is the function s
A vulnerability, which was classified as critical, has been found in Netgear JWNR2000v2 1.0.0.11. Affected by this issue
A vulnerability classified as critical was found in Netgear JWNR2000v2 1.0.0.11. Affected by this vulnerability is the f
A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB A
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automat
A vulnerability classified as critical has been found in Netgear JWNR2000v2 1.0.0.11. Affected is the function check_lan
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (
A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenti
A vulnerability in the “Network Interfaces” functionality of the web application of ctrlX OS allows a remote authenticat
A vulnerability in the “Proxy” functionality of the web application of ctrlX OS allows a remote authenticated (lowprivil
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated
A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacke
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacke
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacke
Delta Electronics ISPSoft version 3.20 is vulnerable to a Stack-Based buffer overflow vulnerability that could allow an
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.5.2 and p
Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 and prior to version 4.11 bundle an implementatio
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is ski
An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes with
A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown fun
A vulnerability was found in PHPGurukul Curfew e-Pass Management System 1.0. It has been declared as critical. Affected
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file uplo
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an u
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows a
CWE-250: Execution with Unnecessary Privileges
CWE-250: Execution with Unnecessary Privileges
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vuln
A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects
Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could all
In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL
CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
CWE-427: Uncontrolled Search Path Element
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affect
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerabi
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by man
A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affe
A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an un
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started