Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a
ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability ex
SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in th
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker t
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. GZI files are used to index block-compressed GZ
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports v
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, in Central Browser mode, Glance
Glances is an open-source system cross-platform monitoring tool. The GHSA-x46r fix (commit 39161f0) addressed SQL inject
HTSlib is a library for reading and writing bioinformatics file formats. CRAM is a compressed format which stores DNA se
A lack of path validation in aaPanel v7.57.0 allows attackers to execute a local file inclusion (LFI), leadingot sensiti
An issue in the VirtualHost configuration handling/parser component of aaPanel v7.57.0 allows attackers to cause a Regul
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 lib
Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToE
In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingr
In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bounds i
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privil
In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count cha
In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: fix wrong reinitialization of ring
In the Linux kernel, the following vulnerability has been resolved: btrfs: do not free data reservation in fallback fro
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix reservation leak in some error paths whe
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server
A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra
The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due t
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in a
When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a
The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signatu
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content s
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the tra
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form defi
Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenti
In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which
An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the se
In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in pe
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m
In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU o
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started