Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 150/1469
8.1
CVE-2026-49164

Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a ne

7.0
CVE-2026-49162

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

7.8
CVE-2026-48581

Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges loca

7.0
CVE-2026-48572

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer all

7.0
CVE-2026-48571

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

8.8
CVE-2026-48564

Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.

8.8
CVE-2026-47632

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges o

7.5
CVE-2026-47296

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized

7.5
CVE-2026-45646

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service ove

7.8
CVE-2026-44800

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notification

7.8
CVE-2026-42982

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate p

8.0
CVE-2026-42975

Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adja

8.1
CVE-2026-42900

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows

8.0
CVE-2026-40400

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

7.5
CVE-2026-40378

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unau

7.3
CVE-2026-15703

A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unkn

8.8
CVE-2026-15429

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling

8.8
CVE-2026-15428

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain na

8.1
CVE-2026-15427

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf

7.5
CVE-2026-9128

A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External

7.5
CVE-2026-9127

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a con

7.5
CVE-2026-9108

A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths withi

7.2
CVE-2026-62643

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTM

7.5
CVE-2026-60081

DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump file

7.5
CVE-2026-59841

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.

7.5
CVE-2026-59836

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 thr

8.6
CVE-2026-59835

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 th

7.5
CVE-2026-59205

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigge

7.5
CVE-2026-59204

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component

7.5
CVE-2026-59199

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-o

7.1
CVE-2026-55651

Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in

7.7
CVE-2026-15392

DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The co

7.5
CVE-2026-12707

Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of p

7.5
CVE-2026-12523

Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by mea

7.5
CVE-2025-53379

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versio

7.5
CVE-2026-60114

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attacke

8.2
CVE-2026-58477

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauth

8.1
CVE-2026-58476

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that al

7.5
CVE-2026-51105

Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via t

8.3
CVE-2026-15736

Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of

8.8
CVE-2026-15696

A vulnerability has been found in Tenda BE12 Pro 16.03.66.23. The impacted element is the function fromVirtualSer of the

8.8
CVE-2026-15695

A flaw has been found in Tenda BE12 Pro 16.03.66.23. The affected element is the function fromDhcpListClient of the file

8.8
CVE-2026-15694

A vulnerability was detected in Tenda BE12 Pro 16.03.66.23. Impacted is the function fromSetIpBind of the file /goform/S

7.7
CVE-2026-14903

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil

8.2
CVE-2026-10672

subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri

7.1
CVE-2026-10671

In Zephyr's kernel pipe implementation, the userspace syscall verifier z_vrfy_k_pipe_init() in kernel/pipe.c used K_SYSC

7.8
CVE-2026-10669

On Xtensa SoCs built with CONFIG_XTENSA_MPU and CONFIG_USERSPACE, arch_buffer_validate() in arch/xtensa/core/mpu.c — the

8.8
CVE-2026-15693

A security vulnerability has been detected in Tenda BE12 Pro 16.03.66.23. This issue affects the function fromSafeMacFil

7.3
CVE-2026-8314

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) compo

7.3
CVE-2026-8313

A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) comp

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started