OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix o
Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)
Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitra
A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators t
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp
PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write v
A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unkn
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename hand
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.
Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle
rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers
rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses co
rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module roo
rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by trigge
rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicio
rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resour
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation
rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote a
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent host
A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authentica
In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2pro
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private ke
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects A
During an internal security assessment, a potential vulnerability was discovered in Lenovo Dock Manager that could allow
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Man
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could all
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files b
rsync before 3.5.0 contains an arbitrary file read vulnerability that allows attackers to read files accessible to the r
rsync before 3.5.0 contains an arbitrary file write vulnerability that allows attackers to write files outside the inten
rsync before 3.5.0 contains a path confinement bypass vulnerability that allows remote clients to escape the intended in
rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbi
rsync before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to write files outside the int
rsync before 3.5.0 contains a path traversal vulnerability that allows remote clients to access files outside the intend
rsync before 3.5.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the rrsync restricte
auth-fetch-mcp is an MCP server that lets AI assistants fetch content from authenticated web pages. Version 3.0.1 implem
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - C
SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less
Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. Se
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLE
During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Le
Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destin
An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial V
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started