Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 808/1469
8.8
CVE-2024-49093

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

7.2
CVE-2024-49091

Windows Domain Name Service Remote Code Execution Vulnerability

7.8
CVE-2024-49090

Windows Common Log File System Driver Elevation of Privilege Vulnerability

7.2
CVE-2024-49089

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

7.8
CVE-2024-49088

Windows Common Log File System Driver Elevation of Privilege Vulnerability

8.8
CVE-2024-49086

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

8.8
CVE-2024-49085

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

7.0
CVE-2024-49084

Windows Kernel Elevation of Privilege Vulnerability

8.8
CVE-2024-49080

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

7.8
CVE-2024-49079

Input Method Editor (IME) Remote Code Execution Vulnerability

7.8
CVE-2024-49076

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

7.5
CVE-2024-49075

Windows Remote Desktop Services Denial of Service Vulnerability

7.8
CVE-2024-49074

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

7.8
CVE-2024-49072

Windows Task Scheduler Elevation of Privilege Vulnerability

7.4
CVE-2024-49070

Microsoft SharePoint Remote Code Execution Vulnerability

7.8
CVE-2024-49069

Microsoft Excel Remote Code Execution Vulnerability

8.2
CVE-2024-49068

Microsoft SharePoint Elevation of Privilege Vulnerability

8.4
CVE-2024-49063

Microsoft/Muzic Remote Code Execution Vulnerability

7.0
CVE-2024-49059

Microsoft Office Elevation of Privilege Vulnerability

8.1
CVE-2024-49057

Microsoft Defender for Endpoint on Android Spoofing Vulnerability

7.5
CVE-2024-47835

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha

7.5
CVE-2024-47778

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover

7.5
CVE-2024-47603

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha

7.5
CVE-2024-47602

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha

7.5
CVE-2024-47601

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha

7.5
CVE-2024-47599

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability ha

7.5
CVE-2024-47596

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtde

7.5
CVE-2024-47546

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in e

7.5
CVE-2024-47545

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in q

7.5
CVE-2024-47544

GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.

7.5
CVE-2024-47543

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discover

7.5
CVE-2024-47542

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discove

7.5
CVE-2024-47541

GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identif

8.1
CVE-2024-45404

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit th

7.8
CVE-2024-43600

Microsoft Office Elevation of Privilege Vulnerability

7.3
CVE-2024-43594

Microsoft System Center Elevation of Privilege Vulnerability

7.5
CVE-2024-37401

An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker

7.5
CVE-2024-37377

A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated a

7.3
CVE-2024-12484

A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects

8.8
CVE-2024-12382

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit he

8.8
CVE-2024-12381

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corr

8.8
CVE-2024-11950

XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows

8.8
CVE-2024-11949

GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability all

8.8
CVE-2024-11947

GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allo

7.8
CVE-2024-11872

Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows lo

7.8
CVE-2024-9845

Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authent

7.8
CVE-2024-8496

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local

8.1
CVE-2024-48912

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an aut

7.2
CVE-2024-47761

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an admin

8.8
CVE-2024-47760

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a techn

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started