Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits o
Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume th
Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed
Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2,
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, a
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched
monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF)
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to cr
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo
Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMart Team Member
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before stor
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched enc
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_
The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi
Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom
Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO
Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement
Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authen
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co
A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade
OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t
OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted
OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al
OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali
OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potenti
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started