Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Messag
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants vikrestaurants allows Cross Site Request Forg
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Watu Quiz watu
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar
Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when
The Front End Users WordPress plugin through 3.2.32 does not sanitise and escape a parameter before outputting it back i
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to m
Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentia
An incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware
A vulnerability, which was classified as critical, was found in H3C GR-3000AX up to V100R006. Affected is the function E
A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is
A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner
ManageWiki is a MediaWiki extension allowing users to manage wikis. Versions before commit f504ed8, are vulnerable to SQ
A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to esca
When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check t
An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been classified as critical. Affected is
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644) and classified as critical. Affected by this
A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by thi
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninst
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been rated as critical. This issue af
A vulnerability was found in Tenda W12 and i24 3.0.0.4(2887)/3.0.0.5(3644). It has been declared as critical. This vulne
A vulnerability has been found in WCMS 11 and classified as critical. Affected by this vulnerability is an unknown funct
A vulnerability, which was classified as critical, was found in WCMS 11. Affected is an unknown function of the file app
The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat
The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the auto-refresh debug log i
The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a
The WP-Syntax WordPress plugin through 1.2 does not properly handle input, allowing an attacker to create a post contain
The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu
The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injecti
z80pack is a mature emulator of multiple platforms with 8080 and Z80 CPU. In version 1.38 and prior, the `makefile-ubunt
When installing Nessus to a non-default location on a Windows host, Nessus versions prior to 10.8.4 did not enforce secu
An issue in WorldCast Systems ECRESO FM/DAB/TV Transmitter v1.10.1 allows authenticated attackers to escalate privileges
An information disclosure vulnerability in the component /socket.io/1/websocket/ of Soundcraft Ui Series Model(s) Ui12 a
A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for certain HP PC products
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system re
Fastify is a fast and low overhead web framework, for Node.js. In versions 5.0.0 to 5.3.0 as well as version 4.29.0, app
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum q
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a ma
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the for
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s p
In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started