Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 811/1469
7.2
CVE-2024-54930

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

7.2
CVE-2024-54922

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote at

7.8
CVE-2024-11608

A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow.

7.8
CVE-2024-11454

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and

8.8
CVE-2024-54926

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allow

7.5
CVE-2024-53450

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents

7.5
CVE-2024-40582

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

7.8
CVE-2024-49600

Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged att

7.2
CVE-2024-54929

KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

7.1
CVE-2024-54226

Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This

7.5
CVE-2024-54225

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.1
CVE-2024-54220

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Servic

7.1
CVE-2024-54219

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehp AIO Contact

7.5
CVE-2024-53790

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core fo

8.2
CVE-2023-51355

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrect

8.1
CVE-2023-49856

Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Acces

7.5
CVE-2023-49831

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-mana

8.2
CVE-2023-49817

Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly

7.1
CVE-2023-49158

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Binh Nguyen LadiAp

8.2
CVE-2023-48286

Missing Authorization vulnerability in mra13 Stripe Payments stripe-payments allows Exploiting Incorrectly Configured Ac

8.6
CVE-2023-47698

Missing Authorization vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Exploiting I

7.5
CVE-2023-25714

Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access C

7.5
CVE-2023-22701

Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control

7.5
CVE-2024-55580

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network ac

8.8
CVE-2024-55579

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network

7.5
CVE-2024-53473

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

7.8
CVE-2024-47115

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improp

8.8
CVE-2024-11501

The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via des

7.5
CVE-2024-12270

The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter

7.2
CVE-2024-11010

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclu

7.8
CVE-2024-53143

In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_object

7.5
CVE-2024-44856

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference

7.5
CVE-2024-44855

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference

7.5
CVE-2024-44854

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference

7.5
CVE-2024-44853

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference

8.8
CVE-2024-0130

NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper au

7.5
CVE-2024-47791

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possibl

8.1
CVE-2024-46874

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credent

7.5
CVE-2024-45722

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an atta

7.5
CVE-2024-47043

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial n

7.8
CVE-2024-11220

A local low-level user on the server machine with credentials to the running OAS services can create and execute a repor

7.5
CVE-2024-54749

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke

8.8
CVE-2024-53691

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul

8.8
CVE-2024-50404

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow re

7.2
CVE-2024-50403

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver

7.2
CVE-2024-50402

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver

7.5
CVE-2024-48868

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o

7.5
CVE-2024-48867

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o

7.5
CVE-2024-48865

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If

7.4
CVE-2024-54137

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started