The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an a
The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When
A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown f
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the
A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/
Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, a
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField
Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b
A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra
A buffer overflow vulnerability exists in the ONVIF GetStreamUri function of LSC Indoor Camera V7.6.32. The application
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider
Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension wi
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSi
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi
In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo
Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatMo
A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an u
A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the
A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypas
Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1
OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attack
A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsO
A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui
Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio
A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /gofo
A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addr
In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API reli
A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-
Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability
Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal v
PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros
Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expr
Kestra is an open-source, event-driven orchestration platform Versions up to and including 1.3.3 render user-supplied fl
Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started