Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 114/1469
7.5
CVE-2026-11605

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG reco

7.5
CVE-2026-11331

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enou

7.5
CVE-2026-62145

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to exe

7.5
CVE-2026-55973

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel

7.5
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with

7.5
CVE-2026-40691

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r

7.5
CVE-2026-32665

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b

8.1
CVE-2026-13190

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities all

7.5
CVE-2026-13189

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell c

8.1
CVE-2026-13187

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentia

8.1
CVE-2026-13186

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence sto

8.1
CVE-2026-13185

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager

7.5
CVE-2026-13184

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKe

7.5
CVE-2026-13183

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic

7.5
CVE-2026-13182

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt f

8.1
CVE-2026-13181

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName process

7.8
CVE-2026-44191

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) a

8.8
CVE-2026-65603

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated pr

8.8
CVE-2026-65602

Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRo

8.8
CVE-2026-65601

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider.

7.5
CVE-2026-65598

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a

8.1
CVE-2026-65596

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based cr

8.8
CVE-2026-65595

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardle

8.8
CVE-2026-65591

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authentic

8.8
CVE-2026-65016

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance

8.8
CVE-2026-65015

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio

7.2
CVE-2026-61391

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers

7.7
CVE-2026-61390

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca

7.5
CVE-2026-57600

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t

8.1
CVE-2026-4773

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authenticati

7.8
CVE-2026-44190

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a

7.8
CVE-2026-44189

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec

8.8
CVE-2026-14551

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are v

7.5
CVE-2026-63047

Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 -

7.5
CVE-2026-45820

fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with

8.8
CVE-2026-3821

Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attack

7.5
CVE-2026-12987

The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-Use

8.8
CVE-2026-12968

The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthent

8.1
CVE-2026-15802

The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation

7.4
CVE-2026-56820

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug

7.5
CVE-2026-56819

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final throug

8.8
CVE-2026-16423

Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage i

7.5
CVE-2026-16422

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an a

8.8
CVE-2026-16421

Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute a

8.8
CVE-2026-16420

Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code

8.8
CVE-2026-16418

Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code

7.8
CVE-2026-16414

Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attack

8.3
CVE-2026-16413

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the

8.8
CVE-2026-8987

Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command ha

7.5
CVE-2026-65319

Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated at

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started