Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports
Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject per
Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues:
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a
RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi
Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce
A user with access to a valid SAML response may impersonate another user under specific conditions.
A Project Resource Manager may gain broader administrative privileges under specific conditions.
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partition
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted v
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, i
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.
Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.
Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository,
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix
POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl
An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality,
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is
The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode
The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto
The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using
The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th
The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable
In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_si
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started