Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 125/1469
7.5
CVE-2026-47247

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak p

7.5
CVE-2026-47063

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

7.4
CVE-2026-47058

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,

7.5
CVE-2026-47057

Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,

7.8
CVE-2026-47054

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.4
CVE-2026-47050

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

7.8
CVE-2026-47047

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

8.2
CVE-2026-47046

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2

8.8
CVE-2026-47037

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The

8.5
CVE-2026-47033

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

8.8
CVE-2026-47031

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Bill Issues). Supported ve

8.1
CVE-2026-47028

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachm

7.4
CVE-2026-47026

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards).

8.1
CVE-2026-47019

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version

7.5
CVE-2026-47018

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

8.7
CVE-2026-47017

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler). Sup

7.1
CVE-2026-47015

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).

8.1
CVE-2026-47014

Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Security). Supported versi

7.3
CVE-2026-47007

Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise

7.2
CVE-2026-47006

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Updat

7.2
CVE-2026-47005

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Updat

8.8
CVE-2026-47004

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Self Updat

7.0
CVE-2026-46999

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery

8.8
CVE-2026-46998

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P

7.1
CVE-2026-46996

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P

8.8
CVE-2026-46995

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata P

8.2
CVE-2026-46993

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next

8.8
CVE-2026-46992

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise

7.3
CVE-2026-46990

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise

7.2
CVE-2026-46988

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector

7.7
CVE-2026-46987

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Applicatio

7.2
CVE-2026-46981

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob

7.2
CVE-2026-46954

Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supporte

7.4
CVE-2026-46943

Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported ve

7.5
CVE-2026-46941

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported

8.0
CVE-2026-46923

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth

7.5
CVE-2026-35287

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita

7.3
CVE-2026-16484

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unkn

7.6
CVE-2026-10680

The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class

8.1
CVE-2026-10678

The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ

8.1
CVE-2026-8982

Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vend

8.2
CVE-2026-65056

mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw

8.8
CVE-2026-64881

The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe

8.6
CVE-2026-63764

LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo

7.3
CVE-2026-63358

FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P

7.1
CVE-2026-56147

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and

7.5
CVE-2026-52476

SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage

7.5
CVE-2026-52474

An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.

7.1
CVE-2026-47697

Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace).

7.5
CVE-2026-47690

MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started