Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to
Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had
Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbi
Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineer
Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten
Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the
Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra
Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside
Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to
Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code in
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS comma
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7
NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection.
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS com
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper cer
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code inj
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs o
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in
The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows
A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write a
OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Comp
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,
A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed i
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. Authorizat
In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `de
Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI wit
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted fil
Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec
Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code executio
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec
Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started