n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject maliciou
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v
A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains a
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains a
A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606).
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi
An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wit
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta
A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary
A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attacke
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissi
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete pos
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update tic
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-a
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extensi
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by expl
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.role
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the
A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low
`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON wit
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token dec
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started