Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 154 and Thunderbird 15
Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thu
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Fir
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Fire
Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was
Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Firefox ESR 1
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 14
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb
Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,
Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 11
ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database an
ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (S
ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTI
ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where
ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that
ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforce
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce t
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through t
grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers wit
Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quote
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints tha
SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/u
SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (incl
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to esca
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer I
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and form
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown fun
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects s
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unkno
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior t
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via
An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, m
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/o
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10
SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths t
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service acco
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows un
Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthe
Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authe
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issu
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticate
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started