Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation o
The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, byp
The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privil
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin
The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida
The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ
The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4
The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial o
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p
The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing
The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escala
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t
The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Word
A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attack
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic
an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authent
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authentic
The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcod
Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path
Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is
The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outpu
The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the
The tourmaster WordPress plugin before 5.3.5 does not escape generated URLs before outputting them in attributes, leadin
Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Se
A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This v
A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unkno
A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unkno
Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex
Buffer Overflow vulnerability in Bento4 mp42avc v.3bdc891602d19789b8e8626e4a3e613a937b4d35 allows a local attacker to ex
Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.
Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScr
The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or i
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in t
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak
A vulnerability has been found in Aridius XYZ up to 20240927 on OpenCart and classified as critical. This vulnerability
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious cod
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenan
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring
The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu
The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in th
Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit hea
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started