The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5,
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iP
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, ma
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, m
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequ
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 1
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Seq
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supp
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad
sf-mcp-server is an implementation of Salesforce MCP server for Claude for Desktop. A command injection vulnerability ex
Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to es
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to
A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction di
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craf
OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper acces
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a
Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a security control bypass vulner
Statmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnera
Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability e
Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage compon
MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the applica
Voyager 1.3.0 contains a directory traversal vulnerability that allows attackers to access sensitive system files by man
TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sendi
SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to c
SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a larg
SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the
SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to
SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to cr
SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to
ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an
RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflo
RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to cr
Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the applicatio
NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by suppl
NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to
NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to
NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to cras
Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by
Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the applicati
Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the applicati
BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attacker
Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by s
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started