Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker
Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to per
Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had comp
Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to pote
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position
Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromi
Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compro
Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a re
Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromi
Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrar
OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allow
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly rece
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authentica
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authe
OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows au
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass
Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is r
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera
Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali
Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/termin
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3
KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrar
Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prio
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exi
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endp
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged age
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be a
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass la
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unaut
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N
tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects
tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I
Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started