Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Th
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In PDF Export
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa
Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib
Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Ap
Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/Fr
A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity
Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 migh
Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actor
Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS d
An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to
Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted r
Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only
Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when a
Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/
Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically termi
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via t
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validatio
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resourc
NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while
NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an una
NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use imp
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows
Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause
Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.1
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.Migration
Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect priv
Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit t
sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on
The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation
Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/aut
Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats
Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, D
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive p
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload i
Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthentic
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vuln
A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service a
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list r
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic
ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started