Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica
TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e
Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication
Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forg
A crafted JavaScript input executed with the QuickJS release 2025-09-13, fixed in commit fcd33c1afa7b3028531f53cd1190a38
GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed
GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary wi
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a
TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro
Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview ren
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behavi
Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal
Incorrect access control in the REST API of Ibexa & Ciril GROUP eZ Platform / Ciril Platform 2.x allows unauthenticated
Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDN
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints.
An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to
OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL qu
PlayJoom 0.10.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL q
ServerZilla 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database que
Nominas 0.27 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL quer
Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by
GPS Tracking System 2.12 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authent
Facturation System 1.0 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary
Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows u
Webiness Inventory 2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrar
Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database file
Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary direct
Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL querie
Gumbo CMS 0.99 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL qu
Easyndexer 1.0 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensi
Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ
Alienor Web Libre 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary
Rmedia SMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database informa
Pedidos 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queri
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by
DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queri
AMPPS 2.7 contains a denial of service vulnerability that allows remote attackers to crash the service by sending malfor
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started