SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/previe
Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless ent
In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv()
The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access func
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to
CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::
GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string
IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librar
Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export de
Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The
PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/
IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated us
A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sen
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnera
The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the
WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL
WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authe
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulatin
radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one K
Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generat
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin
OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses a
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template manag
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prio
Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` disco
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives.
Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connecto
Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector
Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, a
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and
A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves
A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre
A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. Wh
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. Th
LanSpy 2.0.1.159 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction point
LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execu
Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism
MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local att
Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allo
An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix
A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro,
An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes sai
A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use after free of parent_port in cxl_
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started