Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 102/1469
7.5
CVE-2026-50736

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscrib

8.8
CVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*

8.6
CVE-2026-48396

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont

8.6
CVE-2026-48395

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex

7.8
CVE-2026-48394

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48393

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48392

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

8.2
CVE-2026-48391

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex

8.2
CVE-2026-48390

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co

7.8
CVE-2026-48374

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability th

7.8
CVE-2026-18107

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid

8.8
CVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on

8.9
CVE-2026-16496

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t

8.8
CVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.

8.6
CVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT

7.5
CVE-2026-59933

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t

7.7
CVE-2026-59931

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t

7.5
CVE-2026-54635

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.

8.6
CVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in

7.8
CVE-2026-48372

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.5
CVE-2026-67185

TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fi

7.5
CVE-2026-67184

TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to

7.5
CVE-2026-67183

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available me

7.5
CVE-2026-67182

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass acce

8.6
CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle

7.2
CVE-2026-54605

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth:

8.6
CVE-2026-54603

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0

7.5
CVE-2026-54345

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes

7.5
CVE-2026-54332

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow dec

7.6
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification

8.8
CVE-2026-66748

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows user

7.5
CVE-2026-61609

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limite

8.1
CVE-2026-54593

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2,

7.1
CVE-2026-54545

wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlle

8.2
CVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c

7.5
CVE-2026-47427

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.

8.6
CVE-2026-45293

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.

8.2
CVE-2026-43910

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. Fro

7.3
CVE-2026-8164

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk

8.8
CVE-2026-63727

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in th

7.5
CVE-2026-59878

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe

8.8
CVE-2026-7187

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionalit

7.5
CVE-2026-65881

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1

7.3
CVE-2026-62433

Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation

7.3
CVE-2026-62432

The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct

7.5
CVE-2026-62431

The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that

7.5
CVE-2026-62430

Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest ch

7.8
CVE-2026-62428

When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a

8.8
CVE-2026-62427

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

8.8
CVE-2026-62426

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started