A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1
In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_acces
In the Linux kernel, the following vulnerability has been resolved: locking/spinlock/debug: Fix data-race in do_raw_wri
An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ul
Unquoted Search Path or Element vulnerability in NetBT Consulting Services Inc. E-Fatura allows Leveraging/Manipulating
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enab
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Mon
A vulnerability was determined in code-projects Refugee Food Management System 1.0. The affected element is an unknown f
Path Traversal vulnerability in Sharp Display Solutions projectors allows a attacker may access and read any files withi
Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote at
A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.
A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the com
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/d
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIp
A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the fi
The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type
A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin
Yealink RPS before 2025-06-27 allows unauthorized access to information, including AutoP URL addresses. This was fixed b
A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the
A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unk
The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all ver
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor
Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured
A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerabili
The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due
In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windo
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authenticatio
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HT
Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitr
Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious P
AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the P
OCS Inventory NG 2.3.0.0 contains an unquoted service path vulnerability that allows local attackers to escalate privile
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allow
BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitra
A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown fun
A vulnerability was identified in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno
A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unkno
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary p
A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unk
A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of t
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, Langflow provides
Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to
ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being sh
ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content bein
EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. The /api/export interface allows authenticated users to export
The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them
Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerabilit
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started