Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 136/1469
8.8
CVE-2026-62228

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca

7.7
CVE-2026-62227

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that

8.5
CVE-2026-62226

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to

8.8
CVE-2026-62223

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows

7.8
CVE-2026-62222

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plu

7.1
CVE-2026-62219

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validatio

8.8
CVE-2026-62218

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature tha

8.8
CVE-2026-62217

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f

8.0
CVE-2026-62215

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo

7.1
CVE-2026-62212

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea

8.1
CVE-2026-62209

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch

8.8
CVE-2026-62207

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reac

7.1
CVE-2026-62206

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affect

7.1
CVE-2026-62205

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message

8.8
CVE-2026-62203

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to pro

8.8
CVE-2026-62202

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow

7.7
CVE-2026-62201

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l

7.5
CVE-2026-54340

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am

7.5
CVE-2026-39359

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through

7.5
CVE-2026-34150

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov

7.5
CVE-2026-44453

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni

7.5
CVE-2026-44436

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b

7.5
CVE-2026-44435

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 93

8.1
CVE-2026-43978

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess

7.5
CVE-2026-43977

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth

7.5
CVE-2026-59117

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

7.0
CVE-2026-58598

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all

7.7
CVE-2026-57077

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t

7.8
CVE-2026-57076

YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key i

7.8
CVE-2026-53411

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl

8.1
CVE-2026-55173

WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because

7.0
CVE-2026-53410

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl

7.8
CVE-2026-53409

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct

8.6
CVE-2026-44023

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.

8.1
CVE-2026-44019

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.

7.5
CVE-2026-33692

WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through

7.1
CVE-2024-34268

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow

7.3
CVE-2024-32386

Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote at

7.5
CVE-2026-62309

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when

7.3
CVE-2026-62290

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc

7.0
CVE-2026-61389

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt

7.0
CVE-2026-60063

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt

8.2
CVE-2026-49998

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif

7.2
CVE-2026-44982

CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe

7.5
CVE-2026-15352

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a

7.4
CVE-2026-46513

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T

8.1
CVE-2026-46353

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a

8.1
CVE-2026-46351

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit

7.1
CVE-2026-46336

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on

8.1
CVE-2021-27137 KEV

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling function

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started