Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an unauthorized
Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a networ
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netw
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature o
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repos
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who h
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac
A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Ar
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Softw
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from
In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen
The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Websi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co
In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started