The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported m
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, rely
The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte
The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni
A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu
The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t
A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/e
A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co
A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the fil
Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc
A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strc
A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /go
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/u
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element
Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users
open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo
open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover
Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di
open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri
open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA
OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP
A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/
Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(
A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipul
A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Ex
A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Perfo
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebU
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_
A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard
An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac
An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started