An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu
BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDep
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From versi
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, al
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro
An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparo
Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i
Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerabili
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Heap-based Buffer Overflow vulnerabilit
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulne
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started