A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic
A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t
A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que
A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac
A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras
A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker
An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to
An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execut
A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and down
A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker t
A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authent
UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option f
TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v
Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote
Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version
Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket privat
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to th
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log informatio
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write o
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local att
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execut
Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds me
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write ou
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bo
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attac
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded thr
The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the a
The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a se
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the acc
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connecto
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowin
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any au
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data writ
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, wh
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorizat
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before settin
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to includ
Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdem
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started