ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge o
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the re
A vulnerability has been found in Kehua Charging Pile Cloud Platform 1.0 and classified as critical. This vulnerability
A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been classified as critical.
A vulnerability was found in projectworlds Online Admission System 1.0 and classified as critical. Affected by this issu
CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to v
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected
GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, att
A vulnerability was found in code-projects Online Farm System 1.0. It has been declared as critical. Affected by this vu
A vulnerability was found in code-projects Online Farm System 1.0. It has been classified as critical. Affected is an un
A vulnerability was found in code-projects Online Farm System 1.0 and classified as critical. This issue affects some un
A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical. This vulnerability af
vproxy is an HTTP/HTTPS/SOCKS5 proxy server. In versions 2.3.3 and below, untrusted data is extracted from the user-cont
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validat
GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_for
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an un
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Acc
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1.0. Affected by
A vulnerability classified as critical was found in code-projects Exam Form Submission 1.0. Affected by this vulnerabili
Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low p
TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log
An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Befo
Rocket Software Rocket Zena 4.4.1.26 is vulnerable to SQL Injection via the filter parameter.
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents. In v0.6
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1.0. Affected is an unknown
In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/no
The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload
The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to
Use after free in Media Stream in Google Chrome prior to 138.0.7204.183 allowed a remote attacker to potentially exploit
Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability. This vulnerabi
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad
The vulnerability was identified in the code developed specifically for Lenovo. Please visit "Lenovo Product Security Ad
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Pe
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Pe
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Son
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Son
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7.
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, ma
This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.6 and iPadOS 18
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.6 and iPadOS 18.6,
Frequently Asked Questions
What does HIGH severity mean for CVEs?
CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption
How many high severity CVEs exist?
There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize high severity vulnerabilities?
HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.
Detect HIGH Vulnerabilities
CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.
Get Started