Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.
Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticat
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthen
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine t
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by inc
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite att
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spr
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto de
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Pa
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of it
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown functio
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread.
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown functio
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t
Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable t
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal
SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler
SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evalu
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new F
In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitra
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerabil
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker
An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started