Use after free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap co
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out o
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially expl
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially explo
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an
jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Sli
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1
A security flaw has been discovered in CRMEB up to 5.6.3. The affected element is the function appleLogin of the file cr
Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element upda
A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unkn
A vulnerability was detected in Yonyou KSOA 9.0. This affects an unknown part of the file /kmf/user_popedom.jsp of the c
A security vulnerability has been detected in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of t
A weakness has been identified in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the fil
OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Centra
A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the
SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted s
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password au
teklifolustur_app is a web-based PHP application that allows users to create, manage, and track quotes for their clients
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10
ESPHome is a system to control microcontrollers remotely through Home Automation systems. In versions 2025.9.0 through 2
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbDa
OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a s
Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/expr
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @f
A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown functio
WeasyPrint helps web developers to create PDF documents. Prior to version 68.0, a server-side request forgery (SSRF) pro
Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a
An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio
A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This issue affects some unknown
A security flaw has been discovered in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function set
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny
A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the
A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBa
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiF
A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and
A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg o
A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/Config
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /
A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ.
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /gof
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability
A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.j
A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.j
A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of
A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_pla
A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd
esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started