Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 807/1469
8.8
CVE-2024-11689

The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu

8.8
CVE-2024-11443

The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal

8.1
CVE-2024-10111

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all version

7.5
CVE-2024-55658

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint

7.5
CVE-2024-55657

SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists i

7.8
CVE-2024-54529

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS

7.1
CVE-2024-54528

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2,

7.8
CVE-2024-54515

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may b

8.6
CVE-2024-54514

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS

7.5
CVE-2024-54508

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPa

8.8
CVE-2024-54505

A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPa

8.8
CVE-2024-54498

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14

7.8
CVE-2024-54489

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14

7.5
CVE-2024-54479

The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.

7.8
CVE-2024-44291

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2,

7.1
CVE-2024-44245

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, m

7.8
CVE-2024-44225

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS

7.8
CVE-2024-44224

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma

8.5
CVE-2024-42407

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature cou

7.3
CVE-2024-12497

A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affect

8.8
CVE-2024-55587

python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall

7.8
CVE-2024-49142

Microsoft Access Remote Code Execution Vulnerability

7.8
CVE-2024-49138 KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

8.1
CVE-2024-49132

Windows Remote Desktop Services Remote Code Execution Vulnerability

7.5
CVE-2024-49129

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

8.1
CVE-2024-49128

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to

8.1
CVE-2024-49127

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

8.1
CVE-2024-49126

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

8.8
CVE-2024-49125

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.1
CVE-2024-49124

Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

8.1
CVE-2024-49123

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49122

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

7.5
CVE-2024-49121

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

8.1
CVE-2024-49120

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49119

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49118

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

8.8
CVE-2024-49117

Windows Hyper-V Remote Code Execution Vulnerability

8.1
CVE-2024-49116

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.1
CVE-2024-49115

Windows Remote Desktop Services Remote Code Execution Vulnerability

7.8
CVE-2024-49114

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

7.5
CVE-2024-49113

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

8.1
CVE-2024-49108

Windows Remote Desktop Services Remote Code Execution Vulnerability

7.3
CVE-2024-49107

WmsRepair Service Elevation of Privilege Vulnerability

8.1
CVE-2024-49106

Windows Remote Desktop Services Remote Code Execution Vulnerability

8.4
CVE-2024-49105

Remote Desktop Client Remote Code Execution Vulnerability

8.8
CVE-2024-49104

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.8
CVE-2024-49102

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

7.0
CVE-2024-49097

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

7.5
CVE-2024-49096

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

7.0
CVE-2024-49095

Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started