Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0
Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe
Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec
A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. Ho
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s
An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an
In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant us
In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_cry
In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakl
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device remo
In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing net
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake
A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi
A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag
A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started