LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP l
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Hand
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafte
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H
Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi
UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification
Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestC
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow`
Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@pa
Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace env
Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0
A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcf
A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /gofor
Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command process
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Laun
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina
Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extens
LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth
Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap
Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirm
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host
Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoint
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic c
A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/fu
A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in t
A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex o
A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/W
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass
WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike(
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter
In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not p
A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/applica
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started