Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le
NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylis
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen
BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a
Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma
Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by
Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic
Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport
HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac
LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat
DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in
This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst
xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before tak
In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_
In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free i
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`
xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e
WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s
Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb
libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an
libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien
Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M
dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor
Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit
HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso
ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started