Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privil
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Adding array index check to preven
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix handling of plane refcount [W
In the Linux kernel, the following vulnerability has been resolved: kunit: string-stream: Fix a UAF bug in kunit_init_s
Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specia
In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing
RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloo
An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the
RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticate
RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYIND
Dell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privil
The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Cou
The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ para
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missing
The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a missi
Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and ret
The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.
Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vul
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability
Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability
WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the fil
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.
An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, d
Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability
A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users
A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate
In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length tr
Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_
Improper Access Controls allows access to protected views.
Lack of output escaping in the id attribute of menu lists.
An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exist
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in burria Laika Pedig
Missing Authorization vulnerability in 8blocks 1003 Mortgage Application 1003-mortgage-application allows Accessing Func
Cross-Site Request Forgery (CSRF) vulnerability in mmrs151 Prayer Times Anywhere prayer-times-anywhere allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in bozdoz Quote Tweet quote-tweet allows Stored XSS.This issue affects Q
Cross-Site Request Forgery (CSRF) vulnerability in Scott Nelle Uptime Robot uptime-robot allows Stored XSS.This issue af
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started