The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve
Versions of the package expand-object from 0.0.0 are vulnerable to Prototype Pollution in the expand() function in index
Versions of the package bigint-buffer from 0.0.0 are vulnerable to Buffer Overflow in the toBigIntLE() function. Attacke
Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable to
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida
A vulnerability classified as critical has been found in ageerle ruoyi-ai up to 2.0.0. Affected is an unknown function o
A vulnerability was found in ageerle ruoyi-ai up to 2.0.1 and classified as critical. Affected by this issue is some unk
A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.
A vulnerability classified as critical has been found in PHPGurukul e-Diary Management System 1.0. This affects an unkno
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been rated as critical. Affected by this i
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critica
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as criti
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This
A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical.
A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1
A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking Sys
jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Gi
A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected
A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Aff
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical.
This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establish
An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an in
An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind
An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to th
An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API end
insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious param
A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. Thi
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL g
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Using the Relay special node type you c
generator-jhipster-entity-audit is a JHipster module to enable entity audit and audit log page. Prior to 5.9.1, generato
An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via t
Insecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe perm
insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters i
A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by
A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affecte
A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affe
The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If th
A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0.
A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerabili
A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affect
A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by t
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficie
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe whi
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function Shutdown
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vu
A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup t
Missing Authorization vulnerability in Apptivo Apptivo Business Site CRM apptivo-business-site allows Exploiting Incorre
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started