Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 795/1469
7.5
CVE-2024-47924

Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

7.5
CVE-2024-47922

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

8.4
CVE-2024-47921

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

7.5
CVE-2024-47920

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

7.5
CVE-2024-47917

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

7.6
CVE-2024-22063

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can expl

7.3
CVE-2024-13038

A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by

7.3
CVE-2024-13030

A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the fu

7.5
CVE-2024-56749

In the Linux kernel, the following vulnerability has been resolved: dlm: fix dlm_recover_members refcount on error If

7.8
CVE-2024-56740

In the Linux kernel, the following vulnerability has been resolved: nfs/localio: must clear res.replen in nfs_local_rea

7.1
CVE-2024-56721

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Terminate the erratum_1386_microcode a

7.8
CVE-2024-56720

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Several fixes to bpf_msg_pop_data Se

7.5
CVE-2024-56717

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix incorrect IFH SRC_PORT field

7.8
CVE-2024-56715

In the Linux kernel, the following vulnerability has been resolved: ionic: Fix netdev notifier unregister on failure I

7.8
CVE-2024-56709

In the Linux kernel, the following vulnerability has been resolved: io_uring: check if iowq is killed before queuing t

7.3
CVE-2024-13006

A vulnerability, which was classified as critical, has been found in 1000 Projects Human Resource Management System 1.0.

8.8
CVE-2024-56737

GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesys

7.3
CVE-2024-13004

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unk

7.5
CVE-2018-25107

The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a se

7.3
CVE-2024-13002

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b

7.8
CVE-2024-56708

In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unlo

7.8
CVE-2024-56706

In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Fix and protect memory allocation of

8.4
CVE-2024-56704

In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an

7.5
CVE-2024-56703

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix soft lockups in fib6_select_path under hi

7.8
CVE-2024-56699

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix potential double remove of hotplug sl

7.8
CVE-2024-56695

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Use dynamic allocation for CU occupancy

7.5
CVE-2024-56694

In the Linux kernel, the following vulnerability has been resolved: bpf: fix recursive lock when verdict program return

7.8
CVE-2024-56693

In the Linux kernel, the following vulnerability has been resolved: brd: defer automatic disk creation until module ini

7.8
CVE-2024-56692

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on node blkaddr in tru

7.5
CVE-2024-56688

In the Linux kernel, the following vulnerability has been resolved: sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset tran

8.4
CVE-2024-56684

In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_

7.8
CVE-2024-56681

In the Linux kernel, the following vulnerability has been resolved: crypto: bcm - add error check in the ahash_hmac_ini

7.8
CVE-2024-56678

In the Linux kernel, the following vulnerability has been resolved: powerpc/mm/fault: Fix kfence page fault reporting

7.8
CVE-2024-56677

In the Linux kernel, the following vulnerability has been resolved: powerpc/fadump: Move fadump_cma_init to setup_arch(

7.5
CVE-2023-7266

Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may ca

7.3
CVE-2023-7263

Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerabilit

7.7
CVE-2021-37000

Some Huawei wearables have a permission management vulnerability.

7.5
CVE-2021-22484

Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful explo

7.8
CVE-2024-46973

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern

7.8
CVE-2024-46972

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern

7.8
CVE-2024-43705

Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only sy

7.5
CVE-2024-50714

A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive

7.5
CVE-2024-50715

An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command inje

8.8
CVE-2024-56732

HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_c

7.5
CVE-2024-54453

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0

7.5
CVE-2024-39025

Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

7.5
CVE-2024-50945

An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, all

7.3
CVE-2024-12988

A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulne

8.6
CVE-2024-56509

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se

7.6
CVE-2024-56508

LinkAce is a self-hosted archive to collect links of your favorite websites. Prior to 1.15.6, a file upload vulnerabilit

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started