Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Servi
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a De
Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authe
n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with perm
n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, the fix for the heap-use-after
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vi
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereference
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project
A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/ge
Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive da
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path,
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can tri
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_local_move_siz
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 1
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific da
VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create
VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this is
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source por
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSR
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticat
A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gai
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticat
esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF v
The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart S
Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, whe
Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In ve
esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-
iccDEV provides a set of libraries and tools for working with ICC color management profiles. In versions up to and inclu
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encrypti
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -ski
The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started