Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 13/1469
7.8
CVE-2026-75750

Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-75749

Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-71564

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.5
CVE-2026-71443

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de

7.5
CVE-2026-71442

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a

7.8
CVE-2026-71399

Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of

7.8
CVE-2026-71382

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.5
CVE-2026-71360

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application

7.1
CVE-2026-59982

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.8
CVE-2026-48433

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48432

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48431

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48430

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48428

Substance3D - Designer is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.8
CVE-2026-48427

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48426

Substance3D - Designer is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48425

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48424

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48423

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48422

Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code exec

7.8
CVE-2026-48421

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48420

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48419

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48418

Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution

7.8
CVE-2026-48417

Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code exe

7.2
CVE-2026-75498

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin

7.2
CVE-2026-75497

Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with admin

7.2
CVE-2026-75496

Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a

7.8
CVE-2026-64204

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.8
CVE-2026-64203

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.8
CVE-2026-64202

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.8
CVE-2026-64201

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.1
CVE-2026-59189

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59187

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59186

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

7.1
CVE-2026-59184

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

8.8
CVE-2026-55585

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, sche

8.2
CVE-2026-55571

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to

7.5
CVE-2026-55553

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prio

8.2
CVE-2026-47626

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an

8.2
CVE-2026-24263

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause a N

8.2
CVE-2026-24262

NVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an

8.8
CVE-2026-24170

NVIDIA UFM Enterprise contains a vulnerability in the web interface authorization component, where an authenticated user

8.0
CVE-2026-24169

NVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privil

7.5
CVE-2026-19913

The Kaltura HTML5 player (mwEmbed / html5lib) contains a local file disclosure vulnerability due to improper validation

7.8
CVE-2026-16234

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

7.8
CVE-2026-16233

There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure o

8.8
CVE-2026-79784

Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class

8.4
CVE-2026-79774

Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\Sec

7.5
CVE-2026-79770

Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokeniz

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started