Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular
bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is i
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized
Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23
FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.1
ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allow
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary
Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili
An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load
A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution
Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function
Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service v
Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated d
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi
OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server
i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem
18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno.
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escal
lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end
An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a ca
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent
In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Decrement re_receiving on the early exit
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ reco
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for
In the Linux kernel, the following vulnerability has been resolved: net: spacemit: Fix error handling in emac_tx_mem_ma
In the Linux kernel, the following vulnerability has been resolved: spi: amlogic: spifc-a4: Fix DMA mapping error handl
In the Linux kernel, the following vulnerability has been resolved: spi: rockchip-sfc: Fix double-free in remove() call
In the Linux kernel, the following vulnerability has been resolved: ASoC: soc-core: flush delayed work before removing
In the Linux kernel, the following vulnerability has been resolved: serial: caif: hold tty->link reference in ldisc_ope
In the Linux kernel, the following vulnerability has been resolved: bonding: fix type confusion in bond_setup_by_slave(
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix for duplicate device in n
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started