A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d
The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem
The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p
The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi
The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub
The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro
The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz
An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queu
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddN
Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_
A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen
A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alar
Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock
In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren
Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries
S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denia
An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement ty
SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate
Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules
Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v
Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass
The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k
The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac
Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l
PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on
PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p
A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started