Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 128/1469
7.1
CVE-2026-56623

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and

7.5
CVE-2026-56452

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and ser

8.5
CVE-2026-47198

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the

7.1
CVE-2026-47130

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Le

8.1
CVE-2026-47129

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Co

8.1
CVE-2026-13381

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/fil

7.5
CVE-2026-13380

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent

8.8
CVE-2026-53593

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylis

8.6
CVE-2026-53591

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthen

7.5
CVE-2026-15788

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory ju

7.5
CVE-2026-64619

FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated a

7.5
CVE-2026-64194

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::Doma

7.1
CVE-2026-63771

Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by

7.5
CVE-2026-63770

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthentic

7.7
CVE-2026-63769

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport

7.7
CVE-2026-63731

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to dir

8.8
CVE-2026-63108

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attac

7.7
CVE-2026-63107

LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey templat

7.8
CVE-2026-48389

DNG SDK versions 1.7.1 2536 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in

8.8
CVE-2026-12341

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to prot

7.5
CVE-2026-64612

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without inst

8.0
CVE-2026-55626

xrdp is an open source RDP server. In versions 0.10.6 and prior, when an authenticated user session is initialized using

7.5
CVE-2026-48812

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's

8.8
CVE-2026-64206

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before tak

7.8
CVE-2026-64191

In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid

7.8
CVE-2026-64189

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_

7.8
CVE-2026-64188

In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free i

7.1
CVE-2026-58484

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`

7.5
CVE-2026-54538

xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr

7.6
CVE-2026-46701

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e

7.7
CVE-2026-46555

WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes

8.8
CVE-2026-44178

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t

8.2
CVE-2026-41521

xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s

7.1
CVE-2026-39879

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb

7.8
CVE-2026-35591

libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an

7.8
CVE-2026-33327

libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ

7.3
CVE-2026-32825

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

7.3
CVE-2026-32824

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

8.1
CVE-2026-32821

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

7.5
CVE-2026-32820

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

7.5
CVE-2026-32806

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

8.6
CVE-2026-63429

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no

8.2
CVE-2026-46415

The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien

7.5
CVE-2026-45713

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M

7.5
CVE-2026-32807

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

8.4
CVE-2026-28220

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, i

7.5
CVE-2026-26197

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is cor

8.8
CVE-2026-25039

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanit

8.8
CVE-2026-21824

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user perso

8.8
CVE-2026-63090

ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allo

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started