Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containmen
Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal
Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql
pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow a
A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated,
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with re
Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier all
Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att
Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. Th
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is loc
An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite
An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwr
pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a re
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Co
ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that al
An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrit
An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to
A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att
Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low
Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged att
Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5
Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in
An improper access check allows unauthorized access to webservice endpoints.
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was pote
A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uplo
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs acce
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is
In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro
A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/
A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that
A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of
A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /m
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of
Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via
Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code
Object corruption in V8 in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbi
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromi
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started