osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `o
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions p
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to S
hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o
The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability
Actual is a local-first personal finance tool. Prior to version 26.2.1, in multi-user mode (OpenID), the sync API endpoi
A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settin
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi
Zulip is an open-source team collaboration tool. Prior to commit bf28c82dc9b1f630fa8e9106358771b20a0040f7, the API endpo
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to exe
SPIP versions prior to 4.4.10 contain an authentication bypass vulnerability caused by PHP type juggling that allows una
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorizat
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elix
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which cou
An issue in fastCMS before v.0.1.6 allows a local attacker to execute arbitrary code via the PluginController.java compo
Golioth Pouch version 0.1.0, prior to commit 1b2219a1, contains a heap-based buffer overflow in BLE GATT server certific
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, an IDOR vulnerabil
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0.4.1 to latest are vulnerable to ar
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T
Deserialization of Untrusted Data vulnerability in Stylemix uListing ulisting allows Object Injection.This issue affects
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS
The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVu
The installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is
The installer of FinalCode Client provided by Digital Arts Inc. contains an incorrect default permissions vulnerability.
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hostname` API
Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability e
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li
WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository con
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version
WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.
The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0
The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prio
pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can cra
rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Ver
c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `ja
Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`
Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `e
GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs dur
TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A v
Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionali
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started