ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init`
Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are
Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role)
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /co
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the old
Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor
Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control w
Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameter
A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied
A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the
Xibo is an open source digital signage platform with a web content management system and Windows display player software
A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without p
OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges.
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sand
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attac
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mod
OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persis
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, e
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recurs
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-spe
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password re
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core securi
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mas
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remo
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent al
Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Masto
Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Cont
pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submissio
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path trave
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privile
Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandb
TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default
A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially craft
A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, sp
A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started