Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data v
Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised th
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code insid
Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code ins
Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromi
Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the render
Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend
Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code insid
Race in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a s
Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced
Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engag
Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap
Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compro
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on unin
Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across differe
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulne
Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{file
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported vers
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported ver
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported vers
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypas
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. D
Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow a
Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be f
DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/mai
vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in t
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an i
Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivile
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when prope
Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Acce
An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6
An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started