A prototype pollution in the lib.setValue function of @syncfusion/ej2-spreadsheet v27.2.2 allows attackers to cause a De
A prototype pollution in the lib function of php-date-formatter v1.3.6 allows attackers to cause a Denial of Service (Do
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted f
When URL categorization is configured on a virtual server, undisclosed requests can cause TMM to terminate. Note: Softw
When BIG-IP Advanced WAF/ASM Behavioral DoS (BADoS) TLS Signatures feature is configured, undisclosed traffic can case a
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that
When BIG-IP AFM is provisioned with IPS module enabled and protocol inspection profile is configured on a virtual server
When BIG-IP APM Access Profile is configured on a virtual server, undisclosed request can cause TMM to terminate.
When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vuln
When BIG-IP PEM Control Plane listener Virtual Server is configured with Diameter Endpoint profile, undisclosed traffic
When SIP Session and Router ALG profiles are configured on a Message Routing type virtual server, undisclosed traffic ca
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilizatio
When Client or Server SSL profiles are configured on a Virtual Server, or DNSSEC signing operations are in use, undisclo
When a BIG-IP message routing profile is configured on a virtual server, undisclosed traffic can cause an increase in me
When SIP session Application Level Gateway mode (ALG) profile with Passthru Mode enabled and SIP router ALG profile are
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an au
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remo
This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability i
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 pr
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having co
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unau
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can us
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml funct
The Contact Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in
Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability. This vulnerability a
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installa
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successf
In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of
In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (1204.200), the affected application lacks proper validation of
The "NagVis" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrat
Discourse is an open source platform for community discussion. In affected versions an attacker can carefully craft a re
Discourse is an open source platform for community discussion. In affected versions an attacker can make craft an XHR re
reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability al
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started