In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming w
In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split
In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow when reading module E
In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le
In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns fo
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{librar
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor
Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kest
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match aga
In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range
libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shel
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointe
Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code ins
Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code insi
Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to instal
Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised
Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside
An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Ng
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `P
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/t
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath
An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (B
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated at
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i
ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J
A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (
The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started