Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/probl
fast-redact is a package that provides do very fast object redaction. A Prototype Pollution vulnerability in the nestedR
A Prototype Pollution vulnerability in the toCsv function of csvjson versions thru 5.1.0 allows attackers to inject prop
web3-core-method is a package designed to creates the methods on the web3 modules. A Prototype Pollution vulnerability i
toggle-array is a package designed to enables a property on the object at the specified index, while disabling the prope
spmrc is a package that provides the rc manager for spm. A Prototype Pollution vulnerability in the set and config funct
A Prototype Pollution vulnerability in the byGroupAndType function of sassdoc-extras v2.5.1 and before allows attackers
rollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes a
mpregular is a package that provides a small program development framework based on RegularJS. A Prototype Pollution vul
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable
The web3-core-subscriptions is a package designed to manages web3 subscriptions. A Prototype Pollution vulnerability in
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated use
The csvtojson package, a tool for converting CSV data to JSON with customizable parsing capabilities, contains a prototy
Aztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the
Improper Input Validation vulnerability in TOTOLINK X6000R allows Command Injection, File Manipulation.This issue affect
Horilla is a free and open source Human Resource Management System (HRMS). Unauthenticated users can access uploaded res
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Softwa
A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unau
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe
A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches co
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allo
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal. The configuration file handling of the application allows attack
Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co
Integer overflow in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to potentially exploit heap co
Heap buffer overflow in ANGLE in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap
Use after free in Dawn in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap co
Memory corruption while handling invalid inputs in application info setup.
Transient DOS while processing power control requests with invalid antenna or stream values.
Memory corruption while encoding the image data.
Transient DOS while handling command data during power control processing.
Transient DOS while parsing the EPTM test control message to get the test pattern.
Memory corruption due to global buffer overflow when a test command uses an invalid payload type.
Memory corruption due to double free when multiple threads race to set the timestamp store.
Memory corruption while handling repeated memory unmap requests from guest VM.
Memory corruption while processing data sent by FE driver.
Memory corruption while processing message in guest VM.
Memory corruption while processing config_dev IOCTL when camera kernel driver drops its reference to CPU buffers.
memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache
Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is se
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is great
Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments f
Cryptographic issue while performing RSA PKCS padding decoding.
Memory corruption while performing private key encryption in trusted application.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started