@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an
An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33
Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthentic
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A m
Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allow
Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows au
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. T
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne
The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. T
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apach
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This iss
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issu
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affec
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects A
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is
Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling. This iss
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue af
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling. This issue affe
Apache Traffic Server can bypass IP access controls on UDS listeners and through ACL matching errors. This issue affect
Apache Traffic Server can reuse server sessions and tunnels improperly, exposing data across client connections. This i
Description: Missing Authorization in Apache Atlas. A missing authorization vulnerability in Apache Atlas's admin endpoi
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A re
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_
In the Linux kernel, the following vulnerability has been resolved: perf/core: Detach event groups during remove_on_exe
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affe
Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting H
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This
The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server.
Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: fr
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started