Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 817/1469
7.5
CVE-2024-53605

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS

7.1
CVE-2024-53750

Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects Pa

7.1
CVE-2024-53742

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems

7.5
CVE-2024-45520

WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption dur

7.1
CVE-2024-53778

Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows

7.6
CVE-2024-53783

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzar Ahmed Ni Woo

8.1
CVE-2024-53739

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

8.1
CVE-2024-43703

Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads

8.1
CVE-2024-43702

Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access t

7.5
CVE-2024-53623

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive informa

7.5
CVE-2024-36612

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

7.5
CVE-2024-35371

Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient

7.5
CVE-2024-53980

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT)

8.2
CVE-2024-53979

ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop

8.2
CVE-2024-53865

zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "

7.1
CVE-2024-53848

check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the bas

7.5
CVE-2024-36611

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad

8.1
CVE-2024-36623

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult

7.8
CVE-2024-49804

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user

7.2
CVE-2024-11983

Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers wit

7.2
CVE-2024-11982

Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers wi

8.2
CVE-2024-11481

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper han

7.2
CVE-2024-11013

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,

7.5
CVE-2024-11981

Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated atta

8.6
CVE-2024-11980

Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem

7.5
CVE-2024-48651

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th

8.8
CVE-2024-54124

In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.

7.5
CVE-2024-11978

DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this

7.8
CVE-2024-9852

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E

7.0
CVE-2024-8300

Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsub

7.8
CVE-2024-8299

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E

7.3
CVE-2024-11970

A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is a

7.3
CVE-2024-11967

A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is

7.3
CVE-2024-11966

A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects s

7.3
CVE-2024-11965

A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerabil

7.3
CVE-2024-11964

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects

8.8
CVE-2024-11969

The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerabili

7.3
CVE-2024-11962

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnera

8.8
CVE-2024-11960

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f

8.8
CVE-2024-11959

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form

7.8
CVE-2023-52922

In the Linux kernel, the following vulnerability has been resolved: can: bcm: Fix UAF in bcm_proc_show() BUG: KASAN: s

7.1
CVE-2024-53736

Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars custom-shortcode-sidebars allows

7.1
CVE-2024-53734

Cross-Site Request Forgery (CSRF) vulnerability in Jamie O Idealien Category Enhancements idealien-category-enhancements

7.1
CVE-2024-53733

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harshtohit111 Fenc

7.1
CVE-2024-53732

Cross-Site Request Forgery (CSRF) vulnerability in wpwox Footer Flyout Widget footer-flyout-widget allows Stored XSS.Thi

7.5
CVE-2024-52501

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2024-52499

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2024-52498

Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File I

7.5
CVE-2024-52497

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

7.5
CVE-2024-52496

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started