A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by craftin
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i
An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, i
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been rated as critical. Affected by this
A vulnerability classified as critical was found in projectworlds Online Examination System 1.0. Affected by this vulner
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-pr
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attac
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority header
A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected
GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escal
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnera
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected
A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.
The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: C
A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne
A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un
Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability
A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af447
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as critical. Affected
Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when inst
A remote unauthenticated attacker may be able to change the IP adress of the device, and therefore affecting the availab
A vulnerability classified as critical was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). Affected by this vuln
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been crea
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been rated as critical. This issue
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been declared as critical. This vu
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affec
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This issue affects some unknown
A vulnerability has been found in TOTOLINK N150RT 3.4.0-B20190525 and classified as critical. This vulnerability affects
A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown
Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Pa
A vulnerability, which was classified as critical, has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this i
A vulnerability classified as critical was found in TOTOLINK N150RT 3.4.0-B20190525. Affected by this vulnerability is a
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. Affected is an unknown functio
Karaz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.
A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. Affec
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. This vuln
A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This a
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. A
A vulnerability classified as critical was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this v
An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition
A vulnerability, which was classified as critical, has been found in withstars Books-Management-System 1.0. This issue a
A vulnerability was found in withstars Books-Management-System 1.0. It has been rated as critical. Affected by this issu
There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt th
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started