Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 798/1469
7.4
CVE-2024-53165

In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_c

7.8
CVE-2024-53164

In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ordering of qlen adjustment Change

7.5
CVE-2024-3393 KEV

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenti

8.8
CVE-2020-9236

There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does no

7.0
CVE-2020-9222

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on speci

7.8
CVE-2020-9080

There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker c

7.5
CVE-2024-56527

An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.

7.5
CVE-2024-56522

An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a con

7.3
CVE-2024-56520

An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mis

7.5
CVE-2024-56519

An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.

7.3
CVE-2024-12978

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affec

7.3
CVE-2024-12976

A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected b

7.3
CVE-2024-12969

A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affec

8.2
CVE-2024-53850

The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.

7.7
CVE-2024-45600

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated u

7.3
CVE-2024-12968

A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is

7.3
CVE-2024-12967

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln

7.3
CVE-2024-12966

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the fu

7.3
CVE-2024-12965

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been declared as critical. This v

7.3
CVE-2024-12964

A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical.

7.3
CVE-2024-12963

A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this issue is the

8.8
CVE-2024-54907

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.

7.3
CVE-2024-12962

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this vulnera

7.3
CVE-2024-12961

A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affec

7.3
CVE-2024-12960

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0.

8.1
CVE-2024-51540

Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of

7.3
CVE-2024-12959

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit

7.3
CVE-2024-12958

A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. This affects

7.3
CVE-2024-12946

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System

7.3
CVE-2024-12945

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affec

7.3
CVE-2024-12944

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by th

7.3
CVE-2024-12943

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by

8.0
CVE-2023-7300

Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the

7.3
CVE-2024-12942

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been classified as critical. Affe

7.3
CVE-2024-12940

A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Th

8.8
CVE-2024-12652

A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conv

7.3
CVE-2024-12927

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System

7.5
CVE-2024-53291

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An

7.1
CVE-2024-52535

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prio

7.8
CVE-2024-47978

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged

7.5
CVE-2024-12428

The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via t

8.8
CVE-2024-12272

The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPr

8.2
CVE-2019-2483

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th

8.0
CVE-2024-12746

A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privilege

8.0
CVE-2024-12745

A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_sc

8.0
CVE-2024-12744

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSc

7.1
CVE-2024-53162

In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_na

7.8
CVE-2024-53156

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in h

7.1
CVE-2024-53155

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_i

7.5
CVE-2024-53151

In the Linux kernel, the following vulnerability has been resolved: svcrdma: Address an integer overflow Dan Carpenter

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started