A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) compo
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) compo
A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter
A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the
A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handl
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticate
In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Ve
In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx
In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests
For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is parti
An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in B
A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /Job
A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown fun
A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of th
The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through
The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downl
SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted a
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurati
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location
Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2
Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() meth
Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api
9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attack
Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated a
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport t
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup va
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can s
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature th
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that a
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling th
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-t
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower
OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Fe
OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A low
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access r
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-
MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In
A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issu
An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote
Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac
Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulne
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerabil
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started