A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with anoth
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authe
Incorrect Privilege Assignment vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Pr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP24 WP24 Domain C
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Optimize Worldwide
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ianhaycox World Cu
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shinetheme Travele
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was process
A race during concurrent delazification could have led to a use-after-free. This vulnerability was fixed in Firefox 135,
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage t
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash.
Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL
Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension fo
Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to e
Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local
Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows
Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1
A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin
A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo
There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker
The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the
The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA applicatio
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protectin
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands v
Jellystat is a free and open source Statistics App for Jellyfin. In affected versions Jellystat is directly using a user
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where
Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the us
ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which
Geovision GV-ASWeb with the version 6.1.1.0 or less allows attackers to modify POST request method with the GET against
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less tha
Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low p
Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.
An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected f
Digiever DS-2105 Pro 3.1.0.71-11 devices allow time_tzsetup.cgi Command Injection. NOTE: This vulnerability only affects
SQL injection vulnerability in the ZimbraSync Service SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10
Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive inf
ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows
An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF
The BoomBox Theme Extensions plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This
Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started