Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.
libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-fre
GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-3230
AWStats 8.0 is vulnerable to Command Injection via the open function
An issue in the component /Controllers/RestController.php of DreamFactory Core v1.0.3 allows attackers to execute a dire
A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/ed
A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Ex
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS
A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgrad
mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP ser
MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions 11.4 befo
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to versio
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow expli
A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function sub_423B50 of the file
A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /gofo
A flaw has been found in Tenda A18 Pro 02.03.02.28. This issue affects the function setSchedWifi of the file /goform/ope
A vulnerability was detected in Tenda A18 Pro 02.03.02.28. This vulnerability affects the function form_fast_setting_wif
A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the fil
Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authent
The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vuln
Bitcoin Core 0.13.0 through 29.x has an integer overflow.
A vulnerability was determined in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /gof
A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/form
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-
WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL
H3 is a minimal H(TTP) framework. Versions 2.0.0-0 through 2.0.1-rc.14 contain a Host header spoofing vulnerability in t
H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream i
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and be
Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This
Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and
FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln
FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption k
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading
Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, includ
Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: always walk all pending catch
In the Linux kernel, the following vulnerability has been resolved: io_uring: ensure ctx->rings is stable for task work
In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM
In the Linux kernel, the following vulnerability has been resolved: macvlan: observe an RCU grace period in macvlan_com
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally bump set->nel
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started