Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 819/1469
7.3
CVE-2024-11819

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerabilit

7.3
CVE-2024-11818

A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System

7.3
CVE-2024-11817

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as c

7.3
CVE-2024-53675

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in

7.3
CVE-2024-53674

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in

8.1
CVE-2024-53673

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code

7.3
CVE-2024-11622

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in

8.8
CVE-2024-11745

A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function ro

7.3
CVE-2024-11744

A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected

7.4
CVE-2024-8676

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a

7.6
CVE-2024-49053

Microsoft Dynamics 365 Sales Spoofing Vulnerability

8.2
CVE-2024-49052

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p

8.7
CVE-2024-49035 KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privil

8.2
CVE-2024-8114

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.

8.8
CVE-2024-52008

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password

8.1
CVE-2024-32965

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera

8.8
CVE-2024-53555

A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil

7.5
CVE-2024-11407

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled

7.8
CVE-2024-52336

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call

7.2
CVE-2024-9461

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo

7.5
CVE-2024-11702

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored da

8.1
CVE-2024-11700

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to use

8.8
CVE-2024-11699

Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence

8.8
CVE-2024-11697

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"

8.8
CVE-2024-11691

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corrupti

8.4
CVE-2018-5852

An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using d

7.8
CVE-2018-11816

Crafted Binder Request Causes Heap UAF in MediaServer

8.4
CVE-2017-18307

Information disclosure possible while audio playback.

8.4
CVE-2017-18306

Information disclosure due to uninitialized variable.

8.4
CVE-2016-10408

QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory.

7.5
CVE-2024-51569

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l

7.1
CVE-2024-38832

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to vi

7.8
CVE-2024-38831

VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative

7.8
CVE-2024-38830

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative

7.8
CVE-2023-1521

On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the

8.4
CVE-2023-0163

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convi

7.3
CVE-2024-50376

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting

7.2
CVE-2024-50369

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50368

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50367

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50366

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50365

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50364

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50363

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50362

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50361

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50360

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50359

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50358

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactur

8.4
CVE-2018-11952

An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started