A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus f
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec
A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST endpoint intended for fi
A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re
A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configur
A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries.
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foun
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network int
Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati
A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU proce
An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endp
A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution
A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.fil
The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user-switching session to the oper
The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken fro
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a
A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because
A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr
Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insid
Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins
Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds
Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside
Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox
Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially p
Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a
Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially
Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute
Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to i
Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bo
Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to
Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic
Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary co
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack
Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malic
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started