WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authent
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execut
A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function
samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only esca
A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the f
A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file
A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file
Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user ho
OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/userq: fix access to stale wptr mapping
In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cach
In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix use-after-free in scpsys_ge
In the Linux kernel, the following vulnerability has been resolved: wifi: ath5k: do not access array OOB Vincent repor
In the Linux kernel, the following vulnerability has been resolved: flow_dissector: do not dissect PPPoE PFC frames RF
In the Linux kernel, the following vulnerability has been resolved: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl
In the Linux kernel, the following vulnerability has been resolved: isofs: validate Rock Ridge CE continuation extent a
In the Linux kernel, the following vulnerability has been resolved: spi: topcliff-pch: fix use-after-free on unbind Gi
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super(
In the Linux kernel, the following vulnerability has been resolved: dm: fix a buffer overflow in ioctl processing Tony
In the Linux kernel, the following vulnerability has been resolved: clk: microchip: mpfs-ccc: fix out of bounds access
In the Linux kernel, the following vulnerability has been resolved: of: unittest: fix use-after-free in of_unittest_cha
In the Linux kernel, the following vulnerability has been resolved: mtd: docg3: fix use-after-free in docg3_release()
In the Linux kernel, the following vulnerability has been resolved: vmalloc: fix buffer overflow in vrealloc_node_align
In the Linux kernel, the following vulnerability has been resolved: lib: test_hmm: evict device pages on file close to
In the Linux kernel, the following vulnerability has been resolved: mm/alloc_tag: clear codetag for pages allocated bef
In the Linux kernel, the following vulnerability has been resolved: mm/zone_device: do not touch device folio after cal
STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attacker
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticate
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to exec
OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authentic
A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46
A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Thi
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service vi
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-control
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that a
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluat
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, Dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomT
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assista
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRU
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions i
In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_w
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server w
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server T
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started