Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 792/1469
7.8
CVE-2024-56759

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when COWing tree bock and

7.8
CVE-2024-56757

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow w

7.5
CVE-2024-55605

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr

7.2
CVE-2023-6605

A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on

8.6
CVE-2025-21612

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't es

8.8
CVE-2025-21611

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API me

7.5
CVE-2024-8474

OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in t

7.5
CVE-2024-45558

Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without ch

8.4
CVE-2024-45555

Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows u

7.8
CVE-2024-45553

Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global

7.8
CVE-2024-45550

Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.

7.8
CVE-2024-45548

Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.

7.8
CVE-2024-45547

Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryp

7.8
CVE-2024-45546

Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.

7.8
CVE-2024-45542

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

7.8
CVE-2024-45541

Memory corruption when IOCTL call is invoked from user-space to read board data.

7.5
CVE-2024-43064

Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers th

8.4
CVE-2024-21464

Memory corruption while processing IPA statistics, when there are no active clients registered.

8.8
CVE-2024-20154

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio

7.5
CVE-2024-20153

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote

7.5
CVE-2024-20150

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no add

7.5
CVE-2024-20149

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

8.1
CVE-2024-20146

In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote

7.3
CVE-2025-0233

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an

7.3
CVE-2024-41767

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker co

7.5
CVE-2024-41766

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of

7.3
CVE-2025-0210

A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by

8.8
CVE-2024-10957

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions

7.3
CVE-2025-0207

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by th

8.8
CVE-2024-10932

The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.

7.5
CVE-2025-22390

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the C

8.0
CVE-2025-22389

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the C

7.5
CVE-2025-22387

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests fo

7.3
CVE-2025-22386

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the

7.5
CVE-2025-22384

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business l

7.3
CVE-2024-11733

The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t

8.8
CVE-2024-13129

A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th

8.8
CVE-2024-35365

FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically

7.1
CVE-2024-56324

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edi

7.2
CVE-2024-56322

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hi

8.8
CVE-2024-56320

GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to i

7.5
CVE-2024-48814

SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewTyp

7.2
CVE-2024-9138

Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability,

7.8
CVE-2024-53841

In startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead

7.8
CVE-2024-53840

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with

7.8
CVE-2024-53838

In Exynos_parsing_user_data_registered_itu_t_t35 of VendorVideoAPI.cpp, there is a possible out of bounds write due to a

7.8
CVE-2024-53837

In prepare_response of lwis_periodic_io.c, there is a possible out of bounds write due to an integer overflow. This coul

7.8
CVE-2024-53835

there is a possible biometric bypass due to an unusual root cause. This could lead to local escalation of privilege with

7.5
CVE-2024-53834

In sms_DisplayHexDumpOfPrivacyBuffer of sms_Utilities.c, there is a possible out of bounds read due to an incorrect boun

7.8
CVE-2024-53833

In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validat

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started