Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive i
A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some
A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability
A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the
A vulnerability was found in Campcodes Complaint Management System 1.0. It has been declared as critical. This vulnerabi
The parisneo/lollms repository is affected by a timing attack vulnerability in the `authenticate_user` function within t
langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbi
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the huggingface/transformers repository,
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-
A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allo
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom
A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issu
A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this
A vulnerability, which was classified as critical, has been found in UTT HiPER 840G up to 3.1.1-190328. This issue affec
A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknow
A vulnerability classified as critical has been found in UTT 进取 750W up to 3.2.2-191225. This affects an unknown part of
A vulnerability was found in rowboatlabs rowboat up to 8096eaf63b5a0732edd8f812bee05b78e214ee97. It has been rated as cr
A vulnerability was found in SimStudioAI sim up to 37786d371e17d35e0764e1b5cd519d873d90d97b. It has been declared as cri
Server-side request forgery (SSRF) vulnerability exists n multiple versions of Nimesa Backup and Recovery, If this vulne
ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers wit
Vulnerability of bypassing the process to start SA and use related functions on distributed cameras Impact: Successful e
A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This
A critical deserialization vulnerability exists in the run-llama/llama_index library's JsonPickleSerializer component, a
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability aff
A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. Affected by this issue is the functi
A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. Affected by this vulnerability is
A vulnerability has been found in Belkin F9K1122 1.00.33 and classified as critical. This vulnerability affects the func
A vulnerability was found in Belkin F9K1122 1.00.33. It has been classified as critical. Affected is the function formWl
A vulnerability, which was classified as critical, has been found in Belkin F9K1122 1.00.33. Affected by this issue is t
A vulnerability was found in Belkin F9K1122 1.00.33 and classified as critical. This issue affects the function formWanT
A vulnerability, which was classified as critical, was found in Belkin F9K1122 1.00.33. This affects the function formPP
A vulnerability classified as critical was found in Belkin F9K1122 1.00.33. Affected by this vulnerability is the functi
A vulnerability classified as critical has been found in Belkin F9K1122 1.00.33. Affected is the function formPPTPSetup
A vulnerability was found in Belkin F9K1122 1.00.33. It has been rated as critical. This issue affects the function form
A vulnerability was found in Belkin F9K1122 1.00.33. It has been declared as critical. This vulnerability affects the fu
A vulnerability classified as critical has been found in Shenzhen Libituo Technology LBT-T300-T310 up to 2.2.3.6. This a
Incorrect Permission Assignment for Critical Resource vulnerability in Apache APISIX(java-plugin-runner). Local listeni
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset me
In Alinto SOPE SOGo 2.0.2 through 5.12.2, sope-core/NGExtensions/NGHashMap.m allows a NULL pointer dereference and SOGo
Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upo
SetTranslationHandler.php does not validate that the user is an election admin, allowing any (even unauthenticated) user
ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF toke
Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - IPInfo Extension allows Excessive Al
Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may b
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte
In the Linux kernel, the following vulnerability has been resolved: sched/rt: Fix race in push_rt_task Overview ======
In the Linux kernel, the following vulnerability has been resolved: powerpc64/ftrace: fix clobbered r15 during livepatc
In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and export
In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent
In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started