LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An addit
A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected
An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio
An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking an
Rack is a modular Ruby web server interface. The Rack::Sendfile middleware logs unsanitised header values from the X-Sen
A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multipl
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Comme
Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote at
Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption a
A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retri
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can poten
An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Onl
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potenti
On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGF
VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trig
Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this
Permission verification bypass vulnerability in the notification module Impact: Successful exploitation of this vulnerab
Permission bypass vulnerability in the window module Impact: Successful exploitation of this vulnerability may affect se
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the VAPIX Devi
During an annual penetration test conducted on behalf of Axis Communication, Truesec discovered a flaw in the ACAP Appli
The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8
A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects som
A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This af
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this
The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by
A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify column properties in a manner that cou
There is a local file inclusion vulnerability in ArcGIS Server 11.3 and below that may allow a remote, unauthenticated a
There is an improper access control issue in ArcGIS Server versions 11.3 and below on Windows and Linux which, under uni
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint on the admin p
OpenZiti is a free and open source project focused on bringing zero trust to any application. An endpoint(/api/upload) o
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authen
Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing an
FACTION is a PenTesting Report Generation and Collaboration Framework. Authentication is bypassed when an attacker regis
Abacus is a highly scalable and stateless counting API. A critical goroutine leak vulnerability has been identified in t
Rembg is a tool to remove images background. In Rembg 2.0.57 and earlier, the /api/remove endpoint takes a URL query par
A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the
A flaw was found in grub2. When reading data from a squash4 filesystem, grub's squash4 fs module uses user-controlled pa
Various Paragon Software products contain an insecure kernel resource access vulnerability facilitated by the driver not
Various Paragon Software products contain an arbitrary kernel memory vulnerability within biontdrv.sys, facilitated by t
Various Paragon Software products contain an arbitrary kernel memory write vulnerability within biontdrv.sys that is cau
Various Paragon Software products contain an arbitrary kernel memory mapping vulnerability within biontdrv.sys that is c
A DOM Clobbering vulnerability in mavo v0.3.2 allows attackers to execute arbitrary code via supplying a crafted HTML el
A DOM Clobbering vulnerability in umeditor v1.2.3 allows attackers to execute arbitrary code via supplying a crafted HTM
A flaw was found in the HFS filesystem. When reading an HFS volume's name at grub_fs_mount(), the HFS filesystem driver
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started