An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throu
The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j
A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes vi
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across AL
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine p
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowin
better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey delet
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its
## Summary
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing a
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that adve
better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator b
@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization b
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable
GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option p
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and g
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied rem
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC an
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAI
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to valid
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept
better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started