The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext
MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded
The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl
imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is posit
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing
The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_pol
In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netde
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin
In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech
In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate
In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update e
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on a
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double f
In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries th
** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al
When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable,
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter
The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail genera
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to
The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before
The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST
The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au
The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started