Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Fire
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10,
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35,
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() fun
This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i
This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b
Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u
This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi
This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the manage
Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th
AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the
Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability
Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command
Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows n
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile f
OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows
OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to
XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) c
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf
A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted
Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a
The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera
NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)
The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the ema
SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con
A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src
KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft
Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started