Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 12/1469
8.8
CVE-2026-78963

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially exec

8.8
CVE-2026-78956

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to

8.3
CVE-2026-78952

Out of bounds write in Crashpad in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had

8.8
CVE-2026-78950

Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbi

8.8
CVE-2026-78944

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri

8.8
CVE-2026-78938

Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside

8.3
CVE-2026-78934

Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineer

7.5
CVE-2026-78915

Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to poten

8.1
CVE-2026-78913

Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute ar

8.3
CVE-2026-78911

Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

8.8
CVE-2026-78910

Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside

7.5
CVE-2026-78906

Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra

8.8
CVE-2026-78905

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitra

7.5
CVE-2026-78901

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside

8.8
CVE-2026-78899

Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside

7.1
CVE-2026-78892

Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to

8.8
CVE-2026-78891

Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code in

8.1
CVE-2026-65105

NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the

7.8
CVE-2026-65099

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS comma

8.1
CVE-2026-65098

NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause w

7.5
CVE-2026-65097

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download

7.8
CVE-2026-65096

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS

8.5
CVE-2026-65092

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7

8.8
CVE-2026-65091

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection.

7.8
CVE-2026-65090

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS com

7.8
CVE-2026-65089

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause

8.1
CVE-2026-65084

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper cer

7.0
CVE-2026-65082

NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code inj

8.1
CVE-2026-65081

NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution

7.5
CVE-2026-74932

The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs o

7.1
CVE-2026-68515

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-68513

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.0
CVE-2026-66153

The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows

8.8
CVE-2026-66152

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write a

7.1
CVE-2026-59981

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion pictu

7.5
CVE-2026-55099

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Comp

7.2
CVE-2026-45019

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,

8.8
CVE-2026-43670

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed i

8.8
CVE-2026-80049

Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. Authorizat

7.1
CVE-2026-79788

In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `de

7.1
CVE-2026-79786

Coroot's unauthenticated MCP OAuth dynamic client registration endpoint accepts any syntactically valid redirect URI wit

8.1
CVE-2026-78379

Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.

7.5
CVE-2026-55620

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well

7.1
CVE-2026-55609

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear

7.8
CVE-2026-79992

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted fil

7.8
CVE-2026-75770

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-75769

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-75768

Substance3D - Painter is affected by an Untrusted Search Path vulnerability that could result in arbitrary code executio

7.8
CVE-2026-75767

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-75766

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started