Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbit
Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/
Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code
Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted searc
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted o
The application's update service, when checking for updates, loads certain system libraries from a search path that incl
XenForo before 2.3.9 and before 2.2.18 allows remote code execution (RCE) by authenticated, but malicious, admin users.
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This
XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in
XenForo before 2.3.5 allows OAuth2 client applications to request unauthorized scopes. This affects any customer using O
IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could
A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown fun
A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32
SiYuan is a personal knowledge management system. Prior to version 3.6.2, a vulnerability allows crafted block attribute
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the publish service exposes bookmarked blocks
APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo
Nuxt OG Image generates OG Images with Vue templates in Nuxt. Prior to version 6.2.5, the image‑generation component by
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (
Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, D
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variabl
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and
MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetad
An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite crit
A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party oper
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp
An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overw
An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to ove
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under speci
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo
NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorre
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co
A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/we
PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Mi
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical int
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started