Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hccoder Better Use
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBas
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in traveller11 Google
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jonkern WPListCal
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yamna Khawaja Mail
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Farrell wp H
Deserialization of Untrusted Data vulnerability in kkarpieszuk WC Price History for Omnibus wc-price-history allows Obje
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crispweb NC Wishli
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Opentracker Opentr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tsinf TS Comfort D
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P3JX Cf7Save Exten
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mahesh Waghmare MG
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Widgetiz
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Produ
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tripetto WordPress
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and
An attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentContro
The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t
The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit
A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulne
The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware
After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inj
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u
Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use
A post-authentication format string vulnerability in SonicOS management allows a remote attacker to crash a firewall and
A post-authentication stack-based buffer overflow vulnerability in SonicOS management allows a remote attacker to crash
A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be
A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this v
A vulnerability in the Gen7 SonicOS Cloud platform NSv, allows a remote authenticated local low-privileged attacker to e
A Server-Side Request Forgery vulnerability in the SonicOS SSH management interface allows a remote attacker to establis
A vulnerability, which was classified as critical, has been found in KaiYuanTong ECT Platform up to 2.0.0. Affected by t
A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attac
A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part o
A vulnerability, which was classified as critical, was found in wander-chu SpringBoot-Blog 1.0. This affects the functio
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line a
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file sr
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_r
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionari
Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started