stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be u
In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated ag
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio
In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to
In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This coul
In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due t
In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This
In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This cou
In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could
In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand
In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead t
In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow.
In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote
In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overf
In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missi
In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bou
In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio
In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This coul
In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use afte
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution
In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due t
In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code executio
In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to loca
In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to loc
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authent
OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-der
OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that all
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY c
OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata c
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates
OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files
OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influ
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl
DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in
stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima
update_disk_psu_baseline.sh requires password in plain text
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attac
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i
NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data.
NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerabil
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the r
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.
api-gateway container running with root privilege would allow an attacker to escape the container and access host system
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started