An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough r
A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling
multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially c
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is abort
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthori
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive info
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to impro
IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive informatio
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format s
HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cros
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab.,
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint
Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions b
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthent
bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/call
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users t
Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to acce
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt
HyperDX through 1.10.1 fails to enforce role-based access controls in team management endpoints, allowing any team membe
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authen
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file acc
Portkey AI Gateway through 1.15.2 contains a server-side request forgery vulnerability in the /v1/proxy/* route that lac
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middl
Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remot
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before
In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted
Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .verv
PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the w
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows a
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control
Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated r
Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPac
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0,
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{v
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:projec
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/
Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started