LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec
A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the
A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_
This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain e
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove
OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz
A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche
A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess
The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion
When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as e
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPyt
GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP
Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with
A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote
Regex Denial of Service in youtube-regex npm package through version 1.0.5.
A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation
Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column an
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder all
Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster C
The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started