Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 802/1469
7.5
CVE-2024-21547

Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation i

8.1
CVE-2024-12432

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalati

8.8
CVE-2024-12259

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover i

7.5
CVE-2024-12025

The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js

7.8
CVE-2024-47480

Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulne

7.5
CVE-2024-9779

A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-m

7.5
CVE-2024-51175

An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.

7.3
CVE-2024-49194

Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI inject

7.5
CVE-2024-51479

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is

8.8
CVE-2024-53144

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS parin

7.8
CVE-2024-12671

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12670

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul

7.8
CVE-2024-12669

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul

7.8
CVE-2024-12200

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12199

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12198

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12197

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12194

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A

7.8
CVE-2024-12193

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12192

A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability.

7.8
CVE-2024-12191

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability

7.8
CVE-2024-12179

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vul

7.8
CVE-2024-12178

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A

7.8
CVE-2024-11422

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability

8.0
CVE-2024-10476

Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be ab

7.5
CVE-2024-36832

A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via

8.8
CVE-2024-8326

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin

7.2
CVE-2024-12024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting

8.8
CVE-2024-12293

The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi

8.8
CVE-2024-11999

CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the devic

7.9
CVE-2021-26280

Locally installed application can bypass the permission check and perform system operations that require permission.

7.6
CVE-2024-9624

The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu

8.8
CVE-2024-38499

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul

7.0
CVE-2020-12487

Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make

7.1
CVE-2024-56017

Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects

7.5
CVE-2024-52949

iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th

7.5
CVE-2024-37775

Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh

8.0
CVE-2024-37774

A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv

7.2
CVE-2024-55104

Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin

7.2
CVE-2024-55103

Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.

7.6
CVE-2024-8058

An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ director

8.1
CVE-2024-6001

An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the abili

7.8
CVE-2024-4762

An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a l

7.5
CVE-2024-11144

The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The

8.4
CVE-2024-10095

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an i

7.5
CVE-2024-54376

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.6
CVE-2024-54284

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP

7.6
CVE-2024-54283

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedP

7.5
CVE-2024-54279

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tobias Keller WP-NERD Toolki

7.1
CVE-2024-54257

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molefed allows Ref

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started