Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rendere
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-le
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compro
Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromise
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Ag
A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unkn
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist f
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of inco
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transact
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenti
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthe
Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's serv
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to termi
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1bat
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL s
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file hand
Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a re
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remo
Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScript
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` d
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions.
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Subscriber Broken Access Control in AnsPress – Question and answer 4.4.4 versions.
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started