CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administr
The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-a
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs wh
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo
InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token
Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
SiYuan is a personal knowledge management system. Prior to 3.5.10, a privilege escalation vulnerability exists in the pu
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit
Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotati
vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbi
Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of
An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discov
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the Po
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea
An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.
An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd
FreshRSS is a free, self-hostable RSS aggregator. Prior 1.28.0, a bug in the auth logic related to master authentication
An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access t
Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled an
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in linagora Tw
An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in mscdex ssh2 v1.17.0.
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router. An authenticated a
A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExe
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterfac
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formdumpeasysetup.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard534.
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard52.
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attacke
The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st
Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert
A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebSer
If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root dire
By default, jailed processes cannot mount filesystems, including nullfs(4). However, the allow.mount.nullfs option enab
In some cases, the `tcp-setmss` handler may free the packet data and throw an error without halting the rule processing
The rtsol(8) and rtsold(8) programs do not validate the domain search list options provided in router advertisement mess
A weakness has been identified in UTT HiPER 810G up to 1.7.7-1711. This affects the function strcpy of the file /goform/
A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started