picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem
picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun
In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb
The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set befo
In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial
In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets ba
In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get
In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp error
In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream sta
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_fro
In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range
In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error b
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound polic
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during s
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll(
In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one p
In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while que
The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handl
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing
The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se
The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/
The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,
The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th
The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and
The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,
The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,
The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P
The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh
The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save
Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in
Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1
FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email f
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension packa
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started