Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, a
http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the librar
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vul
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use
Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const p
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a
WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t
Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i
http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middlewar
piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run()
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_par
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are n
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is po
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypas
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends la
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name hand
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are s
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlenc
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled inp
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recu
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with t
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy co
IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution an
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 ar
Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and i
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side
The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed a
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started