CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames t
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vul
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template a
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's
OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey ro
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook dat
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-val
Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlRespon
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.3
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expans
Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment
Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with ex
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in th
TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by
TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via u
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and Cac
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t
CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_dec
phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientT
phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint
An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server)
An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-519
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMe
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary
Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. T
In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration fa
In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free in iris_release_int
In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointer
In the Linux kernel, the following vulnerability has been resolved: vsock: fix buffer size clamping order In vsock_upd
In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec
In the Linux kernel, the following vulnerability has been resolved: sctp: revalidate list cursor after sctp_sendmsg_to_
In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on unbind The sta
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Add bounds checking to ib_{get,set}_val
In the Linux kernel, the following vulnerability has been resolved: drm: Set old handle to NULL before prime swap in ch
In the Linux kernel, the following vulnerability has been resolved: HID: appletb-kbd: fix UAF in inactivity-timer clean
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: prevent use-after-free when deleti
In the Linux kernel, the following vulnerability has been resolved: media: iris: fix use-after-free of fmt_src during M
In the Linux kernel, the following vulnerability has been resolved: drm/gem: Fix inconsistent plane dimension calculati
In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop tp_meter sessions during mesh tear
In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject new tp_meter sessions during tea
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started