Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 140/1469
7.8
CVE-2026-48335

Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the con

7.5
CVE-2026-48295

CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclo

8.2
CVE-2026-48290

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary

7.4
CVE-2026-48287

CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execut

8.6
CVE-2026-48275

Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the c

8.8
CVE-2026-46640

Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta

8.1
CVE-2026-46638

Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou

7.5
CVE-2025-56361

A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Lev

7.7
CVE-2026-61520

Simple Machines Forum 2.1 prior to commit 4bf35cf and 3.0 prior to commit b4d23df contains a server-side request forgery

7.5
CVE-2026-52100

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to e

7.5
CVE-2026-49855

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routin

7.7
CVE-2026-49853

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-cop

7.5
CVE-2026-49477

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser

7.5
CVE-2026-49476

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser

7.5
CVE-2026-48815

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 4.1.1, the documented certifi

7.5
CVE-2026-48801

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the pack

7.8
CVE-2026-48370

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48369

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co

7.8
CVE-2026-48367

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48366

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48344

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could resul

7.8
CVE-2026-48343

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48342

Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in t

7.8
CVE-2026-48341

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48340

Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in th

7.8
CVE-2026-48339

Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the co

7.7
CVE-2026-48332

ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature byp

7.7
CVE-2026-48328

ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A l

8.5
CVE-2026-48320

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerabi

7.8
CVE-2026-48311

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context

7.8
CVE-2026-48274

After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-48272

Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary c

7.8
CVE-2026-48270

Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the co

7.8
CVE-2026-48269

Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in

7.8
CVE-2026-47976

Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the c

7.8
CVE-2026-47971

Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i

7.4
CVE-2026-47473

NVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful ex

7.8
CVE-2026-47472

NVIDIA TensorRT-LLM contains a vulnerability in its inter-process communication layer where an attacker with local same-

7.5
CVE-2026-47471

NVIDIA TensorRT-LLM for any platform contains a vulnerability in tensor deserialization, where an attacker could cause a

7.8
CVE-2026-24272

NVIDIA TensorRT contains a vulnerability where an attacker might cause an overflow to a heap-based buffer. A successful

7.8
CVE-2026-24268

NVIDIA TensorRT contains a vulnerability where an attacker might cause a heap-based buffer overflow. A successful exploi

7.8
CVE-2026-24238

NVIDIA TensorRT for contains a vulnerability where an attacker might cause an improper validation of array index. A succ

8.4
CVE-2026-24233

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the restricted unpickler used for model weight deserialization

7.3
CVE-2026-24229

NVIDIA TensorRT-LLM for Linux contains a vulnerability in the disaggregated orchestrator component, where an attacker co

7.5
CVE-2026-15777

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to

8.8
CVE-2026-15776

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitra

8.3
CVE-2026-15774

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the render

8.3
CVE-2026-15772

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised

8.3
CVE-2026-15769

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 al

8.8
CVE-2026-15767

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started