High Severity Vulnerabilities

111.5K CVEs classified as high severity

HIGH
Total CVEs
111.5K
Vulnerabilities
Avg CVSS
8.8
High
Max CVSS
8.8
Highest
Min CVSS
8.8
Lowest

Browse by Severity

High Severity CVEs

Page 26 of 4645
CVSS:8.8(High)

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if...

CVSS:8.8(High)

The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.5 via the Post cus...

CWE-222025
CVSS:8.8(High)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerabili...

CVSS:8.8(High)

Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.

CVSS:8.8(High)

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

CVSS:8.8(High)

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVSS:8.8(High)

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVSS:8.8(High)

Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability

CWE-202025
CVSS:8.8(High)

Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVSS:8.8(High)

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVSS:8.8(High)

Microsoft Digest Authentication Remote Code Execution Vulnerability

CVSS:8.8(High)

Use after free in Inspector in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVSS:8.8(High)

Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS:8.8(High)

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability