Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 126/1469
8.2
CVE-2026-47688

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.

7.3
CVE-2026-47687

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.

7.3
CVE-2026-47685

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.

8.0
CVE-2026-47237

Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio

7.2
CVE-2026-44879

A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta

7.2
CVE-2026-44878

A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r

7.5
CVE-2026-30633

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools

7.1
CVE-2026-64880

Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper

7.8
CVE-2026-59146

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin

7.5
CVE-2026-56852

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

7.5
CVE-2026-50759

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan

8.1
CVE-2026-50758

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c

7.8
CVE-2026-50757

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod

7.5
CVE-2026-50756

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro

7.5
CVE-2026-47667

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i

7.5
CVE-2026-46600

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

7.5
CVE-2026-30632

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

7.5
CVE-2026-15957

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface

8.4
CVE-2026-64877

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor

7.2
CVE-2026-63454

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an

7.2
CVE-2026-63453

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab

8.8
CVE-2026-55084

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL inje

8.3
CVE-2026-47419

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* In

8.1
CVE-2026-47418

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins

8.1
CVE-2026-47417

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins

8.3
CVE-2026-47415

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins

7.6
CVE-2026-47414

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins

8.1
CVE-2026-47412

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut

8.8
CVE-2026-44880

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vuln

7.5
CVE-2026-21579

This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1,

8.0
CVE-2026-21575

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and

7.8
CVE-2026-16493

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manage

7.5
CVE-2026-16243

In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes t

8.1
CVE-2026-47409

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an aut

8.1
CVE-2026-47406

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Ins

8.8
CVE-2026-47405

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a brok

8.8
CVE-2026-47399

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspa

8.1
CVE-2026-47398

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-

7.5
CVE-2026-44907

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo

7.5
CVE-2026-15793

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git s

7.5
CVE-2026-15792

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

7.5
CVE-2026-15791

A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The acti

7.5
CVE-2026-15789

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-contro

8.7
CVE-2026-15724

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user

8.4
CVE-2026-64824

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows a

7.8
CVE-2026-8933

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by

7.5
CVE-2026-65052

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows un

8.8
CVE-2026-59851

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the

8.4
CVE-2026-15226

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler

7.3
CVE-2026-16447

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started