In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys()
In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_writ
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada
A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass
A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick
A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica
A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacke
Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent
music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars
Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot
Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service
DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic
A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an
A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc
OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows
OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin
Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1
Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.
Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen
Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen
IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr
Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una
Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t
An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v
A type confusion vulnerability exists in the EMF functionality of Canva Affinity. A specially crafted EMF file can trigg
An out‑of‑bounds write vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF
A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno
The Angeet ES3 KVM allows a remote, unauthenticated attacker to write arbitrary files, including configuration files or
Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent
JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.
The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess crede
This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0,
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started