SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary c
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloa
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by us
nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of serv
openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allo
openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature pol
openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect
openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key wh
openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied vi
openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing
openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI bl
openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attack
openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples f
openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist s
openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of th
openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metada
openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext w
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST AP
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extr
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch
The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with repl
The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/co
The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in librar
An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::Resource.get_class, Resolv::DNS::Resource:
APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket
Substance3D - Sampler versions 5.1.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could r
An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS)
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows atta
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of S
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 1
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions
A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected p
Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attac
In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on
If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which con
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowi
If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce
In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C:
Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started