FacturaScripts is open-source enterprise resource planning and accounting software. In 2025.71 and earlier, a Stored Cro
The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext r
BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root
IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF
A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN clie
A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restora
A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration modu
A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the
A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attack
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjace
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) and Archer AXE75 v1.0 allows adjacent
Memory Corruption while processing IOCTL call to update sensor property settings with invalid input parameters.
Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers
Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors.
Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input.
Memory Corruption when multiple threads simultaneously access a memory free API.
Memory Corruption when user space address is modified and passed to mem_free API, causing kernel memory to be freed inad
IBM WebSphere Application Server Liberty 17.0.0.3 through 26.0.0.1 could allow a privileged user to upload a zip archive
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres
An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration pres
A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.
An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the
It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting clie
During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helpe
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech
A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploi
In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure wor
In lunary-ai/lunary version 1.2.2, an account hijacking vulnerability exists due to a password reset token leak. A user
A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated a
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in
In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation
In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of serv
In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adja
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if
The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users t
Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of p
The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them bac
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) atta
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary O
A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically mak
EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allo
TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute a
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started