A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/D
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unkno
A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unkn
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of t
A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class o
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affect
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the
A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the fi
A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown funct
A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown function
A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /i
A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of t
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a
The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of
The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it
The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat
A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen
Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero leng
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS f
A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti
The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta
The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n
The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable
Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess
Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co
gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11
Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu
Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion
Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages
In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started