An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload an
Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen
Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (S
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti
SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architectu
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoi
graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per
FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to N
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v
radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted
zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCoo
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul
WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da
HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultG
Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide defaul
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynam
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH),
Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an at
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and execute
Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary comm
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_
Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing da
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the Neu
Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption
xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle a
xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Auth
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when des
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the
Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, w
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when pro
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rende
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect
ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-m
OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t
OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil
The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re
A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f
PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started