A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sopho
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances confi
In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Ac
Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image pr
Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cl
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to pa
A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an u
A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknow
A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication
A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue
A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attac
A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Af
A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remo
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-priv
A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected i
A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 an
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below
An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a lo
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and bel
Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allow
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecros
An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a loc
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and
A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Managemen
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerabi
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to exe
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi
An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerabilit
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affe
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affe
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affe
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affe
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affe
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userla
In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer d
In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries
A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to ex
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Ex
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverag
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started