A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unkn
A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown functio
A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown co
A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of th
The vulnerability arises when a client fetches a tools’ JSON specification, known as a Manual, from a remote Manual Endp
The Doubly – Cross Domain Copy Paste for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all ver
The Extensive VC Addons for WPBakery page builder plugin for WordPress is vulnerable to Local File Inclusion in all vers
The Postem Ipsum plugin for WordPress is vulnerable to unauthorized modification of data to Privilege Escalation due to
The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par
The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress is vulnerable to time-based bl
OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. Th
Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. In versions
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functi
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /a
A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /a
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Sal
An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iO
This issue was addressed with improved state management. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 a
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and i
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, macOS Sequoia 15.
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS
A logic error was addressed with improved error handling. This issue is fixed in macOS Tahoe 26.1. iCloud Private Relay
A mail header parsing issue was addressed with improved checks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS
This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.1. An app may be able to gain root
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4,
The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.3, macOS Tahoe 26. An app
Online Shopping System Advanced 1.0 contains a SQL injection vulnerability in the payment_success.php script that allows
The Preset configuration https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype P
A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown functio
A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This affects an unknown part of the file /goform/formWebAut
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perfor
Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi
WonderCMS 4.3.2 contains a cross-site scripting vulnerability that allows attackers to inject malicious JavaScript throu
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unkn
An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craf
An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overw
A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The
A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec
BuhoNTFS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via
APTIOV contains a vulnerability in BIOS where a user may cause “Improper Handling of Insufficient Permissions or Privile
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for enc
SolarEdge SE3680H ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attac
Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allo
The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any a
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract. This issue affects Apache Fineract:
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization wi
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uni
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started