A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th
A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via
the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr
A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated rem
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects usi
SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attack
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated att
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation
tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, T
Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi
A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a
A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental
A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission
A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b
A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e
A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serv
The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows
Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec
Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started