FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.
Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio
A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper
Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro
CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL inje
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* In
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vuln
This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1,
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manage
In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes t
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a brok
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspa
PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git s
A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.
A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The acti
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-contro
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a
A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by
Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows un
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the
A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started