Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether
Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke
Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi
There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache
A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit
The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v
Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an
Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni
Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) al
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can up
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of use
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3,
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) v
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to
Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exp
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 al
Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who
Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had comprom
Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromise
Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised
Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the
Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the
Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially expl
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started