In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when findi
In the Linux kernel, the following vulnerability has been resolved: comedi: Flush partial mappings in error case If so
In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entrie
The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary
The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora
A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di
A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metri
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di
APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext
Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allo
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the ser
Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code
Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could expl
ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows
home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore functio
home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST n
A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. Thi
An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from
REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Reques
REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery
A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is s
The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in a
The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path
The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e
The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the Ai
A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2
grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c
grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have
grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected ve
systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when
Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attacker
Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can
IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file uplo
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL
A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to r
This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageB
Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device
There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnera
There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerabili
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local
Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows rem
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remo
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Incl
There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to up
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started